CVE-2021-47736

CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cmsimple-xh:cmsimple_xh:1.7.4:-:*:*:*:*:*:*

History

05 Jan 2026, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 7.2

31 Dec 2025, 21:42

Type Values Removed Values Added
References () https://www.cmsimple-xh.org/ - () https://www.cmsimple-xh.org/ - Product
References () https://www.exploit-db.com/exploits/50367 - () https://www.exploit-db.com/exploits/50367 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/cmsimplexh-authenticated-remote-code-execution-via-content-editing - () https://www.vulncheck.com/advisories/cmsimplexh-authenticated-remote-code-execution-via-content-editing - Third Party Advisory
CPE cpe:2.3:a:cmsimple-xh:cmsimple_xh:1.7.4:-:*:*:*:*:*:*
First Time Cmsimple-xh cmsimple Xh
Cmsimple-xh

23 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-23 20:15

Updated : 2026-01-05 14:15


NVD link : CVE-2021-47736

Mitre link : CVE-2021-47736

CVE.ORG link : CVE-2021-47736


JSON object : View

Products Affected

cmsimple-xh

  • cmsimple_xh
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')