Remote Code Execution Vulnerability in GetSimple CMS by GetSimpleCMS-CE
CVE-2026-56662
9.6CRITICAL
What is CVE-2026-56662?
GetSimple CMS, a widely-used content management system, has a vulnerability affecting its community edition prior to version 1.5. The UpdateCE update form lacks an anti-CSRF token, allowing a remote attacker to leverage this weakness. By hosting a page that submits a forged POST request to the update endpoint, an attacker can trick an authenticated administrator into executing a malicious operation. This could lead to remote code execution via the deployed content, compounded by an unescaped URL field that opens the door for HTML injection. Users are encouraged to update to version 1.5 or later to safeguard against this vulnerability.
Affected Version(s)
GetSimpleCMS-CE < 1.5
