CVE-2026-27202

GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication.
Configurations

Configuration 1 (hide)

cpe:2.3:a:getsimple-ce:getsimple_cms:3.3.22:*:*:*:community:*:*:*

History

17 Jun 2026, 10:26

Type Values Removed Values Added
Summary
  • (es) GetSimple CMS es un sistema de gestión de contenidos. Todas las versiones de GetSimple CMS tienen una falla en la característica de Archivos Subidos que permite lecturas arbitrarias de archivos. Este problema sigue sin haber sido solucionado en el momento de la publicación.

24 Feb 2026, 13:08

Type Values Removed Values Added
CPE cpe:2.3:a:getsimple-ce:getsimple_cms:3.3.22:*:*:*:community:*:*:*
References () https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-xhwv-g6q4-h886 - () https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-xhwv-g6q4-h886 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Getsimple-ce getsimple Cms
Getsimple-ce

21 Feb 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-21 00:16

Updated : 2026-06-17 10:26


NVD link : CVE-2026-27202

Mitre link : CVE-2026-27202

CVE.ORG link : CVE-2026-27202


JSON object : View

Products Affected

getsimple-ce

  • getsimple_cms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-23

Relative Path Traversal