Stored Cross-Site Scripting Vulnerability in GetSimple CMS
CVE-2026-71542

8.7HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-71542?

GetSimple CMS and its community edition, GetSimple CMS CE, are affected by a stored Cross-Site Scripting (XSS) vulnerability within the 'Theme to Components' feature. In versions 3.3.22 and earlier, the vulnerability arises from improper handling of the title parameter in the administrative interface. Due to a flaw in the output processing, user-controlled data injected into the title can be exploited to execute arbitrary JavaScript code persistently, providing potential attackers with a vector to compromise the admin panel. As of now, there are no patches available to address this issue, making it crucial for users to adopt preventative measures.

Affected Version(s)

GetSimpleCMS-CE <= 3.3.22

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.