CRITICAL 9.6 CVE-2026-56662 Published 1 Oct 2026

GetSimple CMS CE Update Form CSRF Flaw Leads to Remote Code Execution

Worried this affects your website?

GetSimple CMS CE prior to version 1.5 contains a cross-site request forgery (CSRF) vulnerability in the UpdateCE update form. The form has no anti-CSRF token, and the POST handler performs no token or request-origin verification.

An attacker can host a page that auto-submits a forged POST to the update endpoint. When an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session with no further interaction. Because the deployed content is executed, this yields remote code execution.

The url field is also written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json.

  • Affected versions: prior to 1.5
  • Patched version: 1.5
  • Impact: remote code execution via CSRF; secondary HTML injection

Reference: CVE-2026-56662 on NVD

← Back to Security News