PT-2026-21807 · Unknown · Getsimplecms Community Edition

Vulncheck

·

Published

2026-02-24

·

Updated

2026-02-25

·

CVE-2026-26351

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GetSimpleCMS Community Edition version 3.3.16
Description GetSimpleCMS Community Edition version 3.3.16 has a stored cross-site scripting issue in the Theme to Components functionality within the components.php file. Input to the “slug” field of a component is stored without proper output encoding. The slug parameter is written to XML and rendered in the administrative interface without sanitation, allowing an authenticated administrator to inject malicious script content. This can lead to session hijacking, unauthorized administrative actions, and compromise of the CMS administrative interface when the Components page is viewed by any authenticated user.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-26351
GHSA-95F7-VM92-8GPX

Affected Products

Getsimplecms Community Edition