Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getsimple-ce
Getsimple-ce getsimple Cms |
|
| Vendors & Products |
Getsimple-ce
Getsimple-ce getsimple Cms |
Thu, 01 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to a PHP include() when the page is rendered. Because the include path is never confined, this allows directory-traversal Local File Inclusion: arbitrary local files are included (and, if they contain PHP, executed) when any visitor requests the page. At time of publication, there are no publicly available patches. | |
| Title | GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field | |
| Weaknesses | CWE-22 CWE-98 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-01T19:52:46.391Z
Reserved: 2026-08-06T16:28:51.182Z
Link: CVE-2026-71426
Updated: 2026-10-01T19:51:46.271Z
Status : Deferred
Published: 2026-10-01T20:17:29.260
Modified: 2026-10-01T20:23:46.493
Link: CVE-2026-71426
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:30:23Z