CVE-2026-28495 affects GetSimple CMS (GetSimpleCMS-CE v3.3.22), where the massiveAdmin plugin (v6.0.3) allows an authenticated administrator to overwrite the gsconfig.php file with arbitrary PHP code. This critical vulnerability stems from a lack of CSRF protection, enabling a remote unauthenticated attacker to achieve Remote Code Execution (RCE) via a Cross-Site Request Forgery attack against a logged-in administrator. Rated with a CVSS score of 8.8 (HIGH), successful exploitation grants full control over the web server, compromising confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.22CPE matchmatch criteria | cpe:2.3:a:getsimple-ce:getsimple_cms:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.