Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

GetSimple CMS: Unsecured File Access through Uploaded Files

CVE-2026-27202
Summary

All versions of the GetSimple CMS have a flaw that lets attackers read any file on the server. This is a serious issue because it can allow unauthorized access to sensitive data. Update to the latest version of GetSimple CMS as soon as possible to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
getsimple-ce getsimple_cms 3.3.22 –
Original title
GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time...
Original description
GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication.
nvd CVSS3.1 7.5
nvd CVSS4.0 8.8
Vulnerability type
CWE-22 Path Traversal
CWE-23
Published: 21 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026