Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Authenticated Stored Cross‑Site Scripting
Action: Assess Impact
AI Analysis

Impact

An authenticated user that can edit a GetSimple CMS page can embed malicious JavaScript into the Keywords, Description, Menu text, or Content fields. When an administrator later opens the backup view for that page, the system decodes the previously HTML‑encoded fields and outputs them unescaped, causing the script to run in the admin control panel context. This stored cross‑site scripting allows the attacker to steal admin session cookies, deface the administration interface, or perform arbitrary actions as the administrator.

Affected Systems

The vulnerability affects GetSimple CMS Community Edition, versions 3.3.22 and earlier, where the backup viewer (admin/backup-edit.php) decodes page data during display. The affected product is GetSimpleCMS‑CE; no further vendor or product details are specified in the advisory.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must first be authenticated with permission to edit a page and then rely on an administrator to open the backup edit page. Because the attack occurs when an admin views the backup, the exploitation window is limited to periods when admins are actively using the control panel, but the risk is significant due to the potential for credential theft and lateral movement.

Generated by OpenCVE AI on October 1, 2026 at 20:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch when it becomes available or upgrade to a version newer than 3.3.22.
  • Limit edit permissions to a minimum set of trusted users and enforce role‑based access control so that only authorized content managers can modify pages.
  • Disable or block access to the backup viewer (admin/backup-edit.php) until a fix is released, using web server rules or an application firewall.
  • Implement a Content Security Policy that blocks inline scripts in the admin interface to reduce the impact of any residual XSS payloads.

Generated by OpenCVE AI on October 1, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.
Title GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:39:00.958Z

Reserved: 2026-08-04T21:48:08.612Z

Link: CVE-2026-70650

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:29.110

Modified: 2026-10-01T20:23:46.493

Link: CVE-2026-70650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')