Answer in brief
CVE-2026-56661 records a High severity (CVSS 7.5) vulnerability in GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint. The current sources do not mark it as known exploited. The current feed maps GetSimpleCMS-CE/GetSimpleCMS-CE (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps GetSimpleCMS-CE/GetSimpleCMS-CE (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| GetSimpleCMS-CE/GetSimpleCMS-CEgeneric | <1.5 | 1.5 |
Published upstream
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 1, 2026
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.
Quoted source text, attributed separately from HOL analysis.