Stored Cross-Site Scripting Vulnerability in GetSimpleCMS Community Edition
CVE-2026-26351
What is CVE-2026-26351?
The GetSimpleCMS Community Edition version 3.3.16 is impacted by a stored cross-site scripting (XSS) vulnerability located in the Theme to Components functionality. Specifically, the issue lies in the components.php file where user input submitted to the 'slug' field is not properly sanitized before storage. This oversight leads to the injection of malicious JavaScript, which is persistent and executes every time the affected Components page is accessed by any authenticated user. This vulnerability potentially allows an authenticated administrator to exploit the system, leading to session hijacking, unauthorized administrative actions, and a persistent compromise of the CMS administrative interface. Immediate updates and patches are recommended to mitigate the risk.
Affected Version(s)
GetSimpleCMS-CE 3.3.16
GetSimpleCMS-CE 3.3.22
