[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-56662":6},{"stargazers_count":4,"fetched_at":5},8,"2026-10-01T21:17:52.676Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":36,"aliases":37,"duplicate_of":9,"upstream":38,"downstream":39,"duplicates":40,"related":41,"reserved_at":9,"published_at":42,"modified_at":42,"state":43,"summary":44,"references_raw":51,"kevs":58,"epss":9,"epss_history":59,"metrics":60,"affected":68},"CVE-2026-56662","GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-352","Cross-Site Request Forgery (CSRF)","The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.","weakness","Stable","Compound","Medium",[20,24,28,32],{"id":21,"name":22,"techniques":23},"CAPEC-111","JSON Hijacking (aka JavaScript Hijacking)",[],{"id":25,"name":26,"techniques":27},"CAPEC-462","Cross-Domain Search Timing",[],{"id":29,"name":30,"techniques":31},"CAPEC-467","Cross Site Identification",[],{"id":33,"name":34,"techniques":35},"CAPEC-62","Cross Site Request Forgery",[],[],[],[],[],[],[],"2026-10-01T19:38:30.623Z","Deferred",{"cisa_kev":45,"cisa_ransomware":45,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":46,"severity_score":47,"severity_version":48,"severity_source":49,"severity_vector":50,"severity_status":43},false,"critical",9.6,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",[52],{"url":53,"sources":54,"tags":56},"https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-2rxv-4g4m-573w",[49,55],"nvd",[57],"X Refsource CONFIRM",[],[],[61,66],{"source":49,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":62,"cvss_v4_0":9},{"baseScore":47,"baseSeverity":63,"vectorString":50,"impactScore":64,"exploitabilityScore":65},"CRITICAL",10,7.2,{"source":55,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":67,"cvss_v4_0":9},{"baseScore":47,"baseSeverity":63,"vectorString":50,"impactScore":64,"exploitabilityScore":65},[69],{"ecosystem":9,"name":70,"vendor":71,"product":71,"cpe_part":72,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":73},"GetSimpleCMS-CE","getsimplecms-ce","a",[74],{"version":75,"is_range":76,"range_type":49,"version_start":9,"version_start_type":9,"version_end":77,"version_end_type":78,"fixed_in":9},"\u003C 1.5",true,"1.5","excluding"]