CVE-2026-71542High· 8.7▾ MidnightPoC availableGetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.8 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70650High· 8.8GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-56660Critical· 9.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-56661High· 7.5GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-71426High· 7.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-53953Critical· 9.1GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS
CVE-2026-56662Critical· 9.6GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS