Cross-Site Scripting Vulnerability in GetSimple CMS by GetSimple CMS
CVE-2026-27147
What is CVE-2026-27147?
GetSimple CMS, a widely used content management system, is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of SVG file uploads. Authenticated users have the ability to upload SVG files through the administrative interface, yet these files lack adequate sanitization measures. This flaw enables attackers to embed harmful JavaScript code within the SVG files. When these files are accessed, the malicious script executes within the victim's browser, potentially compromising user data and overall site security. As of now, no fix has been issued for this vulnerability, making it crucial for organizations using GetSimple CMS to assess their exposure and implement necessary security measures.
Affected Version(s)
GetSimpleCMS-CE <= 3.3.22
