Directory Traversal Vulnerability in GetSimple CMS by GetSimple CMS CE
CVE-2026-71426
7.1HIGH
What is CVE-2026-71426?
GetSimple CMS, a widely used content management system, has a vulnerability affecting its community edition (CE). This flaw allows an authenticated user with page-editing rights to enter arbitrary filesystem paths in a page’s template attribute. When the page is accessed on the public front-end, these values are passed unsanitized to a PHP include() function, enabling potential directory traversal. This could lead to unauthorized inclusion and execution of local files, posing a significant risk to website integrity. As of now, there are no patches available to mitigate this issue.
Affected Version(s)
GetSimpleCMS-CE <= 3.3.22
