High severity8.8NVD Advisory· Published Dec 10, 2025· Updated Jun 17, 2026
CVE-2024-58280
CVE-2024-58280
Description
CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/52040nvdExploit
- www.vulncheck.com/advisories/cmsimple-remote-command-execution-via-extensions-configurationnvdThird Party Advisory
- www.cmsimple.orgnvdProduct
- www.cmsimple.org/downloads_cmsimple50/CMSimple_5-15.zipnvdProduct
News mentions
0No linked articles in our index yet.