CVE-2021-47778

Severity CVSS v4.0:
HIGH
Type:
CWE-94 Code Injection
Publication date:
21/01/2026
Last modified:
06/03/2026

Description

GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code through plugin configuration parameters, leading to remote code execution on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:get-simple:getsimplecms:1.1.2:*:*:*:*:*:*:*