Unrated severityNVD Advisory· Published Jan 21, 2026· Updated Apr 7, 2026
GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection
CVE-2021-47778
Description
GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code through plugin configuration parameters, leading to remote code execution on the server.
Affected products
2- Range: =1.1.2
- Range: =1.1.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/49774mitreexploit
- www.vulncheck.com/advisories/getsimple-cms-my-smtp-contact-plugin-php-code-injectionmitrethird-party-advisory
- get-simple.infomitreproduct
News mentions
0No linked articles in our index yet.