Stored Cross-Site Scripting Vulnerability in GetSimple CMS by GetSimple
CVE-2026-70650

8.8HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-70650?

GetSimple CMS contains a stored Cross-Site Scripting (XSS) vulnerability in its page backup viewer located at admin/backup-edit.php. This vulnerability arises from incorrect handling of HTML encoding during the backup process. When a user with editing permissions saves a page, the page fields are stored safely with HTML encoding. However, when accessing the backup viewer, these fields are improperly decoded and displayed without proper re-escaping. As a result, any JavaScript code embedded in the page's Keywords, Description, Menu text, or Content fields can execute in the browser of any administrator who views the backup of the page, potentially leading to unauthorized access or data theft. Currently, there are no publicly available patches to remediate this issue.

Affected Version(s)

GetSimpleCMS-CE <= 3.3.22

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.