ZeroHour

CVE-2026-78834

niche

Authenticated Code Injection in CMSimple 5.22 CoAuthors Plugin

CVSS 3.1
8.8 high
EPSS
<1%p38
Published
()
Modified
AI analysis

CMSimple 5.22, when running the CoAuthors plugin, contains a code injection flaw (CWE-94) in the plugin's content import feature. An authenticated low-privileged user with permission to edit page content can supply controlled imported content, referencing crafted external or uploaded text, which the plugin then processes server-side in a way that executes attacker-controlled code. Successful exploitation yields remote code execution in the context of the web application, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8, network-exploitable with no user interaction required). Only CMSimple 5.22 deployments that have the CoAuthors plugin installed and allow untrusted users to edit pages are affected. No public proof-of-concept, in-the-wild exploitation, or KEV listing is currently known, and EPSS puts 30-day exploitation probability at just 0.2%.

What to do: Inventory CMSimple deployments for the CoAuthors plugin; where it is present, limit page-editing accounts to trusted users or disable the plugin or its import feature until a patched release is available. Since no fixed version is yet listed in the advisory, monitor the vendor for an update and apply it promptly. If compromise is suspected, review for server-side code execution initiated by page editors using the import function.

Affected
CMSimple (CoAuthors plugin)5.22
Estimated exposure
nichelikely hundreds to low thousands of sites (only CMSimple 5.22 instances with the CoAuthors plugin installed) — CMSimple is a lightweight flat-file CMS with a small community install base and no public plugin install counters, and the affected population is further limited to version 5.22 sites that run the niche CoAuthors import extension.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.