CRITICAL 9.1 CVE-2026-53953 Published 1 Oct 2026

GetSimple CMS Password Reset Flaw Enables Admin Account Takeover

Worried this affects your website?

GetSimple CMS is affected by a password reset vulnerability in version 3.3.22. The password reset endpoint can be accessed without authentication, and submitting a reset request for an existing user causes the application to generate a new temporary password and immediately store its hash as the user's password.

The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. The admin login endpoint does not enforce rate limiting or account lockout, so these candidates can be tested online until the correct password is found.

Successful exploitation may lead to administrator account takeover. At the time of publication, there are no publicly available patches.

Reference: CVE-2026-53953 on NVD

← Back to Security News