Get-Simple records
47 published records for vendor get-simple.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 4.3%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')29
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
47 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2019-11231Weaponized | An issue was discovered in GetSimple CMS through 3.3.15.get-simple · getsimple cms · CWE-22 | Critical9.8 | — | 71.6% | May 22, 2019 |
46Plan | CVE-2023-46042No exploit | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().get-simple · getsimplecms · CWE-94 | Critical9.8 | — | 22.6% | Oct 19, 2023 |
42Plan | CVE-2022-41544Proof of concept | GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-ediget-simple · getsimple cms · CWE-94 | Critical9.8 | — | 10.8% | Oct 18, 2022 |
39Monitor | CVE-2023-6188No exploit | GetSimpleCMS theme-edit.php code injectionget-simple · getsimplecms · CWE-94 | Critical9.8 | — | 1.0% | Nov 17, 2023 |
37Monitor | CVE-2020-18191No exploit | GetSimpleCMS-3.3.15 is affected by directory traversal.get-simple · getsimplecms · CWE-22 | Critical9.1 | — | 2.1% | Oct 2, 2020 |
35Monitor | CVE-2013-10032Weaponized | GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Uploadget-simple · getsimplecms · CWE-306 | High8.7 | — | 3.7% | Jul 25, 2025 |
35Monitor | CVE-2018-17103No exploit | An issue was discovered in GetSimple CMS v3.3.13.get-simple · getsimple cms · CWE-352 | High8.8 | — | 0.7% | Sep 16, 2018 |
34Monitor | CVE-2014-8722Proof of concept | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backuget-simple · getsimple cms · CWE-200 | High7.5 | — | 14.4% | Mar 17, 2017 |
34Monitor | CVE-2021-47778No exploit | GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injectionget-simple · getsimplecms · CWE-94 | High8.6 | — | 1.3% | Jan 21, 2026 |
34Monitor | CVE-2021-47860No exploit | GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCEget-simple · getsimplecms · CWE-352 | High8.5 | — | 0.3% | Jan 21, 2026 |
30Monitor | CVE-2021-28976Proof of concept | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.get-simple · getsimplecms · CWE-434 | High7.2 | — | 7.5% | Jun 23, 2021 |
27Monitor | CVE-2020-23839Proof of concept | A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote atget-simple · getsimple cms · CWE-79 | Medium6.1 | — | 10.5% | Sep 1, 2020 |
27Monitor | CVE-2024-11125No exploit | GetSimpleCMS profile.php cross-site request forgeryget-simple · getsimplecms · CWE-352 | Medium6.9 | — | 0.4% | Nov 12, 2024 |
25Monitor | CVE-2018-9173Proof of concept | Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to injget-simple · getsimple cms · CWE-79 | Medium6.1 | — | 2.4% | Apr 1, 2018 |
24Monitor | CVE-2020-18658No exploit | Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.get-simple · getsimplecms · CWE-79 | Medium6.1 | — | 1.4% | Jun 23, 2021 |
24Monitor | CVE-2020-18657No exploit | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_seget-simple · getsimplecms · CWE-79 | Medium6.1 | — | 1.4% | Jun 23, 2021 |
24Monitor | CVE-2020-18659No exploit | Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.phpget-simple · getsimplecms · CWE-79 | Medium6.1 | — | 1.3% | Jun 23, 2021 |
24Monitor | CVE-2020-18660No exploit | GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.get-simple · getsimplecms · CWE-601 | Medium6.1 | — | 1.3% | Jun 23, 2021 |
24Monitor | CVE-2013-1420No exploit | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or Hget-simple · getsimple cms · CWE-79 | Medium6.1 | — | 1.1% | Jan 2, 2020 |
24Monitor | CVE-2021-36601No exploit | GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: get-simple · getsimplecms · CWE-79 | Medium6.1 | — | 0.9% | Aug 10, 2021 |
24Monitor | CVE-2018-16325No exploit | There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.get-simple · getsimple cms · CWE-79 | Medium6.1 | — | 0.8% | Sep 1, 2018 |
24Monitor | CVE-2017-10673No exploit | admin/profile.php in GetSimple CMS 3.x has XSS in a name field.get-simple · getsimple cms · CWE-79 | Medium6.1 | — | 0.7% | Jun 29, 2017 |
21Monitor | CVE-2014-8790No exploit | XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configuracagintranetworks · getsimple cms | Medium5.0 | — | 2.5% | Jan 20, 2015 |
21Monitor | CVE-2014-8723No exploit | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plget-simple · getsimple cms · CWE-200 | Medium5.3 | — | 1.2% | Mar 17, 2017 |
21Monitor | CVE-2020-24861No exploit | GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create get-simple · getsimple cms · CWE-79 | Medium5.4 | — | 0.9% | Oct 1, 2020 |
- CVE-2019-1123160This week
An issue was discovered in GetSimple CMS through 3.3.15.
CriticalCVSS 9.8WeaponizedEPSS 72%get-simple · getsimple cmsMay 22, 2019
- CVE-2023-4604246Plan
An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().
CriticalCVSS 9.8No exploitEPSS 23%get-simple · getsimplecmsOct 19, 2023
- CVE-2022-4154442Plan
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edi
CriticalCVSS 9.8Proof of conceptEPSS 11%get-simple · getsimple cmsOct 18, 2022
- CVE-2023-618839Monitor
GetSimpleCMS theme-edit.php code injection
CriticalCVSS 9.8No exploitEPSS 1%get-simple · getsimplecmsNov 17, 2023
- CVE-2020-1819137Monitor
GetSimpleCMS-3.3.15 is affected by directory traversal.
CriticalCVSS 9.1No exploitEPSS 2%get-simple · getsimplecmsOct 2, 2020
- CVE-2013-1003235Monitor
GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload
HighCVSS 8.7WeaponizedEPSS 4%get-simple · getsimplecmsJul 25, 2025
- CVE-2018-1710335Monitor
An issue was discovered in GetSimple CMS v3.3.13.
HighCVSS 8.8No exploitEPSS 1%get-simple · getsimple cmsSep 16, 2018
- CVE-2014-872234Monitor
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backu
HighCVSS 7.5Proof of conceptEPSS 14%get-simple · getsimple cmsMar 17, 2017
- CVE-2021-4777834Monitor
GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection
HighCVSS 8.6No exploitEPSS 1%get-simple · getsimplecmsJan 21, 2026
- CVE-2021-4786034Monitor
GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE
HighCVSS 8.5No exploitEPSS 0%get-simple · getsimplecmsJan 21, 2026
- CVE-2021-2897630Monitor
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
HighCVSS 7.2Proof of conceptEPSS 8%get-simple · getsimplecmsJun 23, 2021
- CVE-2020-2383927Monitor
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote at
MediumCVSS 6.1Proof of conceptEPSS 10%get-simple · getsimple cmsSep 1, 2020
- CVE-2024-1112527Monitor
GetSimpleCMS profile.php cross-site request forgery
MediumCVSS 6.9No exploitEPSS 0%get-simple · getsimplecmsNov 12, 2024
- CVE-2018-917325Monitor
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inj
MediumCVSS 6.1Proof of conceptEPSS 2%get-simple · getsimple cmsApr 1, 2018
- CVE-2020-1865824Monitor
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
MediumCVSS 6.1No exploitEPSS 1%get-simple · getsimplecmsJun 23, 2021
- CVE-2020-1865724Monitor
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_se
MediumCVSS 6.1No exploitEPSS 1%get-simple · getsimplecmsJun 23, 2021
- CVE-2020-1865924Monitor
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
MediumCVSS 6.1No exploitEPSS 1%get-simple · getsimplecmsJun 23, 2021
- CVE-2020-1866024Monitor
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
MediumCVSS 6.1No exploitEPSS 1%get-simple · getsimplecmsJun 23, 2021
- CVE-2013-142024Monitor
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or H
MediumCVSS 6.1No exploitEPSS 1%get-simple · getsimple cmsJan 2, 2020
- CVE-2021-3660124Monitor
GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL:
MediumCVSS 6.1No exploitEPSS 1%get-simple · getsimplecmsAug 10, 2021
- CVE-2018-1632524Monitor
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
MediumCVSS 6.1No exploitEPSS 1%get-simple · getsimple cmsSep 1, 2018
- CVE-2017-1067324Monitor
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
MediumCVSS 6.1No exploitEPSS 1%get-simple · getsimple cmsJun 29, 2017
- CVE-2014-879021Monitor
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configura
MediumCVSS 5.0No exploitEPSS 3%cagintranetworks · getsimple cmsJan 20, 2015
- CVE-2014-872321Monitor
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) pl
MediumCVSS 5.3No exploitEPSS 1%get-simple · getsimple cmsMar 17, 2017
- CVE-2020-2486121Monitor
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create
MediumCVSS 5.4No exploitEPSS 1%get-simple · getsimple cmsOct 1, 2020