Sploitus

CVE-2025-48492

No indexed exploits for CVE-2025-48492 yet

GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote Code Execution (RCE). This issue is set to be patched in version 3.3.22.

Affected products
Getsimple Cms
Getsimple-ce Getsimple Cms
< 3.3.22
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.9% (58th percentile)
Weakness
CWE-77
NVD status
Analyzed
Published
2025-05-30
CVE-2025-48492 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-48492 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-48492 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.