Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to a PHP include() when the page is rendered. Because the include path is never confined, this allows directory-traversal Local File Inclusion: arbitrary local files are included (and, if they contain PHP, executed) when any visitor requests the page. At time of publication, there are no publicly available patches.
Published: 2026-10-01
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Local File Inclusion leading to arbitrary file reading and potential PHP code execution
Action: ApplyPatch
AI Analysis

Impact

An authenticated user who can edit page content on GetSimple CMS CE can store a file path in the "template" attribute of a page. When that page is viewed, the CMS passes this path unsanitized to PHP’s include() function. Because the path can include directory traversal characters, an attacker can craft a page that causes the server to include any file on the filesystem, including files that contain PHP code. If such code is included, it is executed in the context of the web application, giving the attacker code‑execution privileges on the server. The vulnerability enables disclosure of sensitive files, modification of content, or full control of the affected system.

Affected Systems

GetSimple CMS Community Edition is affected in all releases 3.3.22 and older. The issue exists only for users with page‑editing rights and can be exploited on any HTTP front‑end that renders the page.

Risk and Exploitability

The CVSS score is 7.1, indicating a high severity. EPSS data is not available, so the current estimated probability of exploitation is unknown but likely low to moderate. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session with page‑editing rights; an attacker who has compromised credentials or who can create a privileged user account can set the malicious template path and then trigger the inclusion by having any visitor load the affected page. Public disclosure is recent, so an immediate fix is preferable before a public exploit is discovered.

Generated by OpenCVE AI on October 1, 2026 at 20:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest GetSimple CMS CE release once the vendor publishes an official patch.
  • Audit all pages for custom "template" values; reset any paths that resolve to sensitive directories or to arbitrary files.
  • Restrict page‑editing permissions so that only administrators can modify the template field, and configure PHP’s open_basedir setting to confine includes to approved directories.

Generated by OpenCVE AI on October 1, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to a PHP include() when the page is rendered. Because the include path is never confined, this allows directory-traversal Local File Inclusion: arbitrary local files are included (and, if they contain PHP, executed) when any visitor requests the page. At time of publication, there are no publicly available patches.
Title GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field
Weaknesses CWE-22
CWE-98
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:52:46.391Z

Reserved: 2026-08-06T16:28:51.182Z

Link: CVE-2026-71426

cve-icon Vulnrichment

Updated: 2026-10-01T19:51:46.271Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:29.260

Modified: 2026-10-01T20:23:46.493

Link: CVE-2026-71426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')