VYPR
Unrated severityNVD Advisory· Published Dec 10, 2025· Updated Apr 7, 2026

CMSimple 5.15 Remote Command Execution via Extensions Configuration

CVE-2024-58280

Description

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.