CVE-2022-41544

CRITICAL

GetSimple CMS <3.3.16 - RCE

Title source: llm

Description

GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Youssef Muhammad · pythonwebappsphp
https://www.exploit-db.com/exploits/51475
nomisec WORKING POC 1 stars
by yosef0x01 · poc
https://github.com/yosef0x01/CVE-2022-41544
nomisec WORKING POC
by nopgadget · poc
https://github.com/nopgadget/CVE-2022-41544
nomisec WORKING POC
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2022-41544

Scores

CVSS v3 9.8
EPSS 0.6380
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
get-simple/getsimple_cms 3.3.16
Published Oct 18, 2022
Tracked Since Feb 18, 2026