CVE-2024-58280
CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.94%
- CWE
- CWE-403
- Published
- 2025-12-10
- Last modified
- 2026-04-07
Affected products
- CMSimple CMSimple
Weakness type
Related vulnerabilities
- CVE-2026-33263 — When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with...
- CVE-2026-16526 — Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
- CVE-2026-40042 — Pachno 1.0.6 Wiki TextParser XML External Entity Injection
- CVE-2025-15114 — Ksenia Security lares Home Automation 1.6 PIN Exposure Vulnerability
- CVE-2024-21626 — runc container breakout through process.cwd trickery and leaked fds