Vulnerabilities
CVE-2021-47735 - CMSimple 5.4 Authenticated Remote Code Execution via Template Editing
CVE ID : CVE-2021-47735 Published : Dec. 23, 2025, 8:15 p.m. | 32 minutes ago Description : CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
PHP
Impact:
remote code execution
Source: Telegram CVE Monitor