PT-2026-97032 · Cmsimple · Cmsimple

CVE-2026-88418

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMSimple version 5.24
Description CSRF protection is disabled by default, rendering the csrfProtection() function ineffective for state-changing admin requests and omitting the csrf token hidden field in admin forms. Since administrator authentication relies solely on cookies without CSRF token enforcement, an unauthenticated attacker can trick a logged-in administrator's browser into sending a forged content-save request. This request can include a text payload with a scripting marker that is stored in content/content.php. Subsequently, the evaluate cmsimple scripting() function in functions.php executes the marker body using PHP eval(), allowing persistent remote code execution on the web server for all visitors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88418

Affected Products

Cmsimple