getsimple-ce kayıtları
getsimple-ce üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %10
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-55085İstismar yok | GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which cagetsimple-ce · getsimple cms · CWE-94 | Kritik9,8 | — | %0,9 | 16 Ara 2024 |
35İzleyin | CVE-2026-27202İstismar yok | GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerabilitygetsimple-ce · getsimple cms · CWE-22 | Yüksek8,8 | — | %0,5 | 20 Şub 2026 |
35İzleyin | CVE-2026-28495İstismar yok | GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.phpgetsimple-ce · getsimple cms · CWE-352 | Yüksek8,8 | — | %0,3 | 10 Mar 2026 |
35İzleyin | CVE-2024-55088İstismar yok | GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.getsimple-ce · getsimple cms · CWE-352 | Yüksek8,8 | — | %0,3 | 18 Ara 2024 |
34İzleyin | CVE-2025-48492İstismar yok | GetSimple CMS RCE in Edit componentgetsimple-ce · getsimple cms · CWE-77 | Yüksek8,6 | — | %0,9 | 30 May 2025 |
34İzleyin | CVE-2026-27161İstismar yok | Unauthenticated Information Disclosure via .htaccess Reliance in Sensitive Directoriesgetsimple-ce · getsimple cms · CWE-200 | Yüksek8,7 | — | %0,5 | 20 Şub 2026 |
28İzleyin | CVE-2024-55086İstismar yok | In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the bagetsimple-ce · getsimple cms · CWE-918 | Yüksek7,2 | — | %0,4 | 18 Ara 2024 |
28İzleyin | CVE-2026-27146İstismar yok | GetSimple CMS: Cross-Site Request Forgery (CSRF) in File Upload Allows Arbitrary Uploadsgetsimple-ce · getsimple cms · CWE-352 | Yüksek7,1 | — | %0,2 | 20 Şub 2026 |
27İzleyin | CVE-2026-27147İstismar yok | GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated)getsimple-ce · getsimple cms · CWE-79 | Orta6,9 | — | %0,2 | 20 Şub 2026 |
19İzleyin | CVE-2026-26351İstismar yok | GetSimpleCMS-CE < 3.3.22 Stored XSS via components.phpgetsimple-ce · getsimple cms · CWE-79 | Orta4,8 | — | %0,4 | 24 Şub 2026 |
- CVE-2024-5508539İzleyin
GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which ca
KritikCVSS 9,8İstismar yokEPSS %1getsimple-ce · getsimple cms16 Ara 2024
- CVE-2026-2720235İzleyin
GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1getsimple-ce · getsimple cms20 Şub 2026
- CVE-2026-2849535İzleyin
GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.php
YüksekCVSS 8,8İstismar yokEPSS %0getsimple-ce · getsimple cms10 Mar 2026
- CVE-2024-5508835İzleyin
GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.
YüksekCVSS 8,8İstismar yokEPSS %0getsimple-ce · getsimple cms18 Ara 2024
- CVE-2025-4849234İzleyin
GetSimple CMS RCE in Edit component
YüksekCVSS 8,6İstismar yokEPSS %1getsimple-ce · getsimple cms30 May 2025
- CVE-2026-2716134İzleyin
Unauthenticated Information Disclosure via .htaccess Reliance in Sensitive Directories
YüksekCVSS 8,7İstismar yokEPSS %0getsimple-ce · getsimple cms20 Şub 2026
- CVE-2024-5508628İzleyin
In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the ba
YüksekCVSS 7,2İstismar yokEPSS %0getsimple-ce · getsimple cms18 Ara 2024
- CVE-2026-2714628İzleyin
GetSimple CMS: Cross-Site Request Forgery (CSRF) in File Upload Allows Arbitrary Uploads
YüksekCVSS 7,1İstismar yokEPSS %0getsimple-ce · getsimple cms20 Şub 2026
- CVE-2026-2714727İzleyin
GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated)
OrtaCVSS 6,9İstismar yokEPSS %0getsimple-ce · getsimple cms20 Şub 2026
- CVE-2026-2635119İzleyin
GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php
OrtaCVSS 4,8İstismar yokEPSS %0getsimple-ce · getsimple cms24 Şub 2026