Skip to content
Noroxi

getsimple-ce records

10 published records for vendor getsimple-ce.

All records

10 records
  • GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which ca

    CriticalCVSS 9.8No exploitEPSS 1%

    getsimple-ce · getsimple cmsDec 16, 2024

  • GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    getsimple-ce · getsimple cmsFeb 20, 2026

  • GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.php

    HighCVSS 8.8No exploitEPSS 0%

    getsimple-ce · getsimple cmsMar 10, 2026

  • GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.

    HighCVSS 8.8No exploitEPSS 0%

    getsimple-ce · getsimple cmsDec 18, 2024

  • GetSimple CMS RCE in Edit component

    HighCVSS 8.6No exploitEPSS 1%

    getsimple-ce · getsimple cmsMay 30, 2025

  • Unauthenticated Information Disclosure via .htaccess Reliance in Sensitive Directories

    HighCVSS 8.7No exploitEPSS 0%

    getsimple-ce · getsimple cmsFeb 20, 2026

  • In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the ba

    HighCVSS 7.2No exploitEPSS 0%

    getsimple-ce · getsimple cmsDec 18, 2024

  • GetSimple CMS: Cross-Site Request Forgery (CSRF) in File Upload Allows Arbitrary Uploads

    HighCVSS 7.1No exploitEPSS 0%

    getsimple-ce · getsimple cmsFeb 20, 2026

  • GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated)

    MediumCVSS 6.9No exploitEPSS 0%

    getsimple-ce · getsimple cmsFeb 20, 2026

  • GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php

    MediumCVSS 4.8No exploitEPSS 0%

    getsimple-ce · getsimple cmsFeb 24, 2026