Cross-Site Scripting Vulnerability in GetSimple CMS by GetSimple CMS
CVE-2026-27147

6.9MEDIUM

Key Information:

Vendor
CVE Published:
20 February 2026

What is CVE-2026-27147?

GetSimple CMS, a widely used content management system, is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of SVG file uploads. Authenticated users have the ability to upload SVG files through the administrative interface, yet these files lack adequate sanitization measures. This flaw enables attackers to embed harmful JavaScript code within the SVG files. When these files are accessed, the malicious script executes within the victim's browser, potentially compromising user data and overall site security. As of now, no fix has been issued for this vulnerability, making it crucial for organizations using GetSimple CMS to assess their exposure and implement necessary security measures.

Affected Version(s)

GetSimpleCMS-CE <= 3.3.22

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.