CVE-2026-70650
GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.
| CWE | CWE-79 |
| Vendor | getsimplecms-ce |
| Product | getsimplecms-ce |
| Published | Oct 1, 2026 |
Get instant alerts for getsimplecms-ce getsimplecms-ce
Be the first to know when new unknown vulnerabilities affecting getsimplecms-ce getsimplecms-ce are published โ delivered to Slack, Telegram or Discord.