← Vulnerability feed

Vulnerability record · CVE-2024-58280 · published 10 December 2025

CVE-2024-58280: Cmsimple vulnerability

Cmsimple · Cmsimple

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.

8.6 CVSS 4.0 High EPSS 0.94% · top 40.6% CWE-403 · CWE-403
8.6CVSS 4.0 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
26 Sep 2026Last modified by NVD

Description

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-58280 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43741Cmsimple path traversal vulnerabilityCMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading…EPSS 4.7%9.1CVE-2024-57548Cmsimple incorrect default permissions vulnerabilityCMSimple 5.16 allows the user to edit log.php file via print page.EPSS 0.47%8.6CVE-2021-47734Cmsimple php remote file inclusion vulnerabilityCMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute ar…EPSS 0.78%8.6CVE-2021-47735Cmsimple code injection vulnerabilityCMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template…EPSS 0.88%7.5CVE-2024-57547Cmsimple incorrect permission assignment vulnerabilityInsecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the Functional…EPSS 0.57%7.5CVE-2024-57549Cmsimple path traversal vulnerabilityCMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.EPSS 0.66%7.5CVE-2024-57546Cmsimple vulnerabilityAn issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.EPSS 0.58%7.4CVE-2024-33423Cmsimple vulnerabilityCross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a craft…EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2024-58280), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.