Stored Cross-Site Scripting Vulnerability in GetSimple CMS
CVE-2026-71542
8.7HIGH
What is CVE-2026-71542?
GetSimple CMS and its community edition, GetSimple CMS CE, are affected by a stored Cross-Site Scripting (XSS) vulnerability within the 'Theme to Components' feature. In versions 3.3.22 and earlier, the vulnerability arises from improper handling of the title parameter in the administrative interface. Due to a flaw in the output processing, user-controlled data injected into the title can be exploited to execute arbitrary JavaScript code persistently, providing potential attackers with a vector to compromise the admin panel. As of now, there are no patches available to address this issue, making it crucial for users to adopt preventative measures.
Affected Version(s)
GetSimpleCMS-CE <= 3.3.22
