Stored Cross-Site Scripting Vulnerability in GetSimpleCMS Community Edition
CVE-2026-26351

4.8MEDIUM

Key Information:

Vendor
CVE Published:
24 February 2026

What is CVE-2026-26351?

The GetSimpleCMS Community Edition version 3.3.16 is impacted by a stored cross-site scripting (XSS) vulnerability located in the Theme to Components functionality. Specifically, the issue lies in the components.php file where user input submitted to the 'slug' field is not properly sanitized before storage. This oversight leads to the injection of malicious JavaScript, which is persistent and executes every time the affected Components page is accessed by any authenticated user. This vulnerability potentially allows an authenticated administrator to exploit the system, leading to session hijacking, unauthorized administrative actions, and a persistent compromise of the CMS administrative interface. Immediate updates and patches are recommended to mitigate the risk.

Affected Version(s)

GetSimpleCMS-CE 3.3.16

GetSimpleCMS-CE 3.3.22

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Beatriz Fresno Naumova
VulnCheck
.