Getsimple Cms
Vendor:
First CVE: Dec 16, 2024 · Active for 1 year
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Getsimple Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 16, 2024
19 months ago
Most Recent CVE
Mar 10, 2026
138 days ago
CVE Severity & Scoring
Getsimple Cms10 CVEs
30%
60%
10%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low3 (30.0%)
High3 (30.0%)
None4 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28495HIGH GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig. | Mar 10, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-27161HIGH GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apa | Feb 21, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-27202HIGH GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been | Feb 21, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-55085CRITICAL GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RC | Dec 16, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-48492HIGH GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a co | May 30, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-55088HIGH GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module. | Dec 18, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-26351MEDIUM GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality wit | Feb 24, 2026 | 4.8 | 22 | NO | NO |
CVE-2026-27147MEDIUM GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the adminis | Feb 21, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-27146MEDIUM GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker ca | Feb 21, 2026 | 4.5 | 20 | NO | NO |
CVE-2024-55086HIGH In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system. | Dec 18, 2024 | 7.2 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Getsimple Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.3.22 | 1 | 7.5 | 0.5% | 0 | 0 |
| 3.3.19 | 3 | 8.6 | 0.5% | 0 | 0 |