Stored Cross-Site Scripting Vulnerability in GetSimple CMS by GetSimple
CVE-2026-70650
What is CVE-2026-70650?
GetSimple CMS contains a stored Cross-Site Scripting (XSS) vulnerability in its page backup viewer located at admin/backup-edit.php. This vulnerability arises from incorrect handling of HTML encoding during the backup process. When a user with editing permissions saves a page, the page fields are stored safely with HTML encoding. However, when accessing the backup viewer, these fields are improperly decoded and displayed without proper re-escaping. As a result, any JavaScript code embedded in the page's Keywords, Description, Menu text, or Content fields can execute in the browser of any administrator who views the backup of the page, potentially leading to unauthorized access or data theft. Currently, there are no publicly available patches to remediate this issue.
Affected Version(s)
GetSimpleCMS-CE <= 3.3.22
