getsimple-ce records
10 published records for vendor getsimple-ce.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 10%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-55085No exploit | GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which cagetsimple-ce · getsimple cms · CWE-94 | Critical9.8 | — | 0.9% | Dec 16, 2024 |
35Monitor | CVE-2026-27202No exploit | GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerabilitygetsimple-ce · getsimple cms · CWE-22 | High8.8 | — | 0.5% | Feb 20, 2026 |
35Monitor | CVE-2026-28495No exploit | GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.phpgetsimple-ce · getsimple cms · CWE-352 | High8.8 | — | 0.3% | Mar 10, 2026 |
35Monitor | CVE-2024-55088No exploit | GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.getsimple-ce · getsimple cms · CWE-352 | High8.8 | — | 0.3% | Dec 18, 2024 |
34Monitor | CVE-2025-48492No exploit | GetSimple CMS RCE in Edit componentgetsimple-ce · getsimple cms · CWE-77 | High8.6 | — | 0.9% | May 30, 2025 |
34Monitor | CVE-2026-27161No exploit | Unauthenticated Information Disclosure via .htaccess Reliance in Sensitive Directoriesgetsimple-ce · getsimple cms · CWE-200 | High8.7 | — | 0.5% | Feb 20, 2026 |
28Monitor | CVE-2024-55086No exploit | In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the bagetsimple-ce · getsimple cms · CWE-918 | High7.2 | — | 0.4% | Dec 18, 2024 |
28Monitor | CVE-2026-27146No exploit | GetSimple CMS: Cross-Site Request Forgery (CSRF) in File Upload Allows Arbitrary Uploadsgetsimple-ce · getsimple cms · CWE-352 | High7.1 | — | 0.2% | Feb 20, 2026 |
27Monitor | CVE-2026-27147No exploit | GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated)getsimple-ce · getsimple cms · CWE-79 | Medium6.9 | — | 0.2% | Feb 20, 2026 |
19Monitor | CVE-2026-26351No exploit | GetSimpleCMS-CE < 3.3.22 Stored XSS via components.phpgetsimple-ce · getsimple cms · CWE-79 | Medium4.8 | — | 0.4% | Feb 24, 2026 |
- CVE-2024-5508539Monitor
GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which ca
CriticalCVSS 9.8No exploitEPSS 1%getsimple-ce · getsimple cmsDec 16, 2024
- CVE-2026-2720235Monitor
GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerability
HighCVSS 8.8No exploitEPSS 1%getsimple-ce · getsimple cmsFeb 20, 2026
- CVE-2026-2849535Monitor
GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.php
HighCVSS 8.8No exploitEPSS 0%getsimple-ce · getsimple cmsMar 10, 2026
- CVE-2024-5508835Monitor
GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.
HighCVSS 8.8No exploitEPSS 0%getsimple-ce · getsimple cmsDec 18, 2024
- CVE-2025-4849234Monitor
GetSimple CMS RCE in Edit component
HighCVSS 8.6No exploitEPSS 1%getsimple-ce · getsimple cmsMay 30, 2025
- CVE-2026-2716134Monitor
Unauthenticated Information Disclosure via .htaccess Reliance in Sensitive Directories
HighCVSS 8.7No exploitEPSS 0%getsimple-ce · getsimple cmsFeb 20, 2026
- CVE-2024-5508628Monitor
In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the ba
HighCVSS 7.2No exploitEPSS 0%getsimple-ce · getsimple cmsDec 18, 2024
- CVE-2026-2714628Monitor
GetSimple CMS: Cross-Site Request Forgery (CSRF) in File Upload Allows Arbitrary Uploads
HighCVSS 7.1No exploitEPSS 0%getsimple-ce · getsimple cmsFeb 20, 2026
- CVE-2026-2714727Monitor
GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated)
MediumCVSS 6.9No exploitEPSS 0%getsimple-ce · getsimple cmsFeb 20, 2026
- CVE-2026-2635119Monitor
GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php
MediumCVSS 4.8No exploitEPSS 0%getsimple-ce · getsimple cmsFeb 24, 2026