CVE-2026-28495Disclosure(getsimple-ce / getsimple_cms)

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code via the gsconfig editor module. The form lacks CSRF protection, enabling a remote unauthenticated attacker to exploit this via Cross-Site Request Forgery against a logged-in admin, achieving Remote Code Execution (RCE) on the web server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • getsimple_cms

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • 5 total mentions across 1 day

Affected systems

Products
getsimple_cms

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-10: 5Technical Details · 2026-03-10: 403-10
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28495 GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite… https://www.cve.org/CVERecord?id=CVE-2026-28495 ----- Traducción: CVE-2026-28495 Get… http://infoflow.cloud`

    Post summary

    CVE-2026-28495 is a disclosure for GetSimple CMS’s massiveAdmin plugin, where authenticated administrators can overwrite files, but no proof of concept, exploit code, patch, or active exploitation is provided.

    0000015
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28495 GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite… https://www.cve.org/CVERecord?id=CVE-2026-28495

    Post summary

    The tweet announces that CVE‑2026‑28495 allows an authenticated administrator of GetSimpleCMS to overwrite configuration via the massiveAdmin plugin, but does not provide any PoC, exploit, or mitigation details.

    00000185
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28495: CRITICAL] Vulnerability in GetSimpleCMS-CE v3.3.22 allows RCE. The massiveAdmin plugin v6.0.3 allows attackers to overwrite gsconfig.php, leading to PHP code execution. #cybersecurity#cve,CVE-2026-28495,#cybersecurity https://cvefind.com/CVE-2026-28495

    Post summary

    The tweet announces a critical RCE vulnerability in GetSimpleCMS‑CE v3.3.22 via the massiveAdmin plugin, enabling attackers to overwrite gsconfig.php and execute PHP code.

    0000047
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28495 - Critical GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php con... https://www.thehackerwire.com/vulnerability/CVE-2026-28495/ https://t.co/sHHQ5OnWMP

    Post summary

    A new critical vulnerability (CVE-2026-28495) in GetSimple CMS’s massiveAdmin plugin allows authenticated administrators to overwrite gsconfig.php.

    0000026
    133 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28495: GetSimple CMS has CSRF to Remote... CSRF-to-RCE chain via gsconfig.php overwrite - one malicious email with embedded form triggers full server compromise w... https://zerodaysignal.com/vulnerability/CVE-2026-28495 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new CVE (CVE-2026-28495) affecting GetSimple CMS, describing a CSRF-to-RCE chain via gsconfig.php overwriting that can lead to full server compromise.

    0000045
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetsimple-cegetsimple_cms---

Explore more