CVE-2024-58280 - CMSimple 5.15 Remote Command Execution via Extensions Configuration

CVE-2024-58280 - CMSimple 5.15 Remote Command Execution via Extensions Configuration

CVE ID : CVE-2024-58280 Published : Dec. 10, 2025, 10:16 p.m. | 39 minutes ago Description : CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Dec. 10, 2025
Affected Product: PHP

Source: Telegram CVE Monitor