---
id: CVE-2026-70650
title: >-
  GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is
  the community edition of that CMS
summary: >-
  GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is
  the community edition of that CMS. In versions 3.3.22 and prior, an
  authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the
  page backup viewe…
severity: high
cvss: 8.8
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-79
vendor: GetSimpleCMS-CE
product: GetSimpleCMS-CE
affected:
  - GetSimpleCMS-CE <= 3.3.22
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T20:23:46.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-70650'
references:
  - url: >-
      https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-p6vf-2xr7-mcf4
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-01T19:58:57.565Z'
---

## Overview

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
