HIGH
CMSimple
CVE published 2026-09-22
CVE-2026-88418
CVE-2026-88418 is a high-severity vulnerability in CMSimple 5.24 that allows unauthenticated attackers to execute remote code on the web server. The vulnerability is caused by CSRF protection being disabled by default, which enables an attacker to induce a logged-in administrator's browser to issue a forged content-save request with a text payload containing a scripting marker. This marker is stored verba [truncated]