Infoflowcloud@infoflowcloudDisclosure
CVE-2026-28495 is a disclosure for GetSimple CMS’s massiveAdmin plugin, where authenticated administrators can overwrite files, but no proof of concept, exploit code, patch, or active exploitation is provided.
CVE@CVEnewDisclosure
The tweet announces that CVE‑2026‑28495 allows an authenticated administrator of GetSimpleCMS to overwrite configuration via the massiveAdmin plugin, but does not provide any PoC, exploit, or mitigation details.
CVEFind.com@CveFindComDisclosure
The tweet announces a critical RCE vulnerability in GetSimpleCMS‑CE v3.3.22 via the massiveAdmin plugin, enabling attackers to overwrite gsconfig.php and execute PHP code.
The Hacker Wire@TheHackerWireDisclosure
A new critical vulnerability (CVE-2026-28495) in GetSimple CMS’s massiveAdmin plugin allows authenticated administrators to overwrite gsconfig.php.
0day Signal@0dayPublishingDisclosure
The tweet announces a new CVE (CVE-2026-28495) affecting GetSimple CMS, describing a CSRF-to-RCE chain via gsconfig.php overwriting that can lead to full server compromise.