CVE-2026-27202 HIGH

CVE-2026-27202: GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerability

Vendor Getsimplecms-Ce
Product GetSimpleCMS-CE
Weakness CWE-23
Published February 20, 2026
Last update February 25, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication.

Key dates

02Disclosure timeline

February 20, 2026 CVE published
February 25, 2026 Record updated