PULSE
FEED
ransomincransom reclama a Sangre de Cristo Electric Association · US · Energy & Utilitiesransomnetrunner reclama a Main Place Mall · MY · Retail & E-Commerceransomkrybit reclama a EURODITEL/RESOTELECOM · Technologyransomkairos reclama a Slate Valley Unified School District · US · Educationransomkrybit reclama a DISK PRECISION GROUP - diskprecision.com · US · Manufacturingransombooba project reclama a FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" · BR · Government & Defenseransombooba project reclama a ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C · US · Healthcareransommorpheus reclama a Superior Plating Technology CO · Manufacturingransomnightspire reclama a C*ro *nty *es · Not Foundransomakira reclama a Wesmar · US · Manufacturingransomakira reclama a DPL Group · Otherransomakira reclama a Krycler, Ervin, Taubman & Kaminsky · Professional Servicesransomredact reclama a Graybar Electric Company, Inc. · US · Manufacturingransomincransom reclama a Rimrock Foundation · US · Otherransomincransom reclama a Sangre de Cristo Electric Association · US · Energy & Utilitiesransomnetrunner reclama a Main Place Mall · MY · Retail & E-Commerceransomkrybit reclama a EURODITEL/RESOTELECOM · Technologyransomkairos reclama a Slate Valley Unified School District · US · Educationransomkrybit reclama a DISK PRECISION GROUP - diskprecision.com · US · Manufacturingransombooba project reclama a FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" · BR · Government & Defenseransombooba project reclama a ASSOCIATED GASTROENTEROLOGISTS OF CENTRAL NEW YORK, P.C · US · Healthcareransommorpheus reclama a Superior Plating Technology CO · Manufacturingransomnightspire reclama a C*ro *nty *es · Not Foundransomakira reclama a Wesmar · US · Manufacturingransomakira reclama a DPL Group · Otherransomakira reclama a Krycler, Ervin, Taubman & Kaminsky · Professional Servicesransomredact reclama a Graybar Electric Company, Inc. · US · Manufacturingransomincransom reclama a Rimrock Foundation · US · Other
← Todos los CVEs
CVE Watch1 oct 2026

CVE-2026-71426

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior,

CVSS

—

Sin CVSS

EPSS

—

KEV

—

Exploit Today

0

0-100

Publicado: 1 oct 2026 · Última mod.: 1 oct 2026 · CWE-22 · CWE-98

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to a PHP include() when the page is rendered. Because the include path is never confined, this allows directory-traversal Local File Inclusion: arbitrary local files are included (and, if they contain PHP, executed) when any visitor requests the page. At time of publication, there are no publicly available patches.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-714276.8 MED
—
——0Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.8h
CVE-2026-55393—
—
——0Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.10h
CVE-2026-1042869.8 CRÍ
—
KEV—50Fortinet FortiMail Path Traversal Vulnerability10h
CVE-2026-552317.2 ALT
—
——0Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/passwd, and delete config/db.php to push a site back into install mode for a full takeover. This issue has been patched in version 1.0.8.6.11h
CVE-2026-1038846.5 MED
—
——0A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.10h
CVE-2026-1018896.5 MED
—
——0The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation in computeExtractVariables() and validateImportedSiteVsPackage() to cause primeMoverDoDelete() to remove directories outside the intended extraction path, potentially deleting critical WordPress directories such as wp-admin and rendering the site inoperable.14h