PT-2026-5564 · Unknown · Simple-Cms

Published

2026-02-01

·

Updated

2026-02-01

·

CVE-2021-47919

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Simple CMS version 2.1
Description The software contains a non-persistent cross-site scripting issue in the preview.php file. The id parameter is susceptible to malicious script injection through a GET request, potentially allowing attackers to execute arbitrary scripts, hijack user sessions, or conduct phishing attacks. The vulnerable parameter is id.
Recommendations Apply necessary input validation and sanitization to the id parameter in the preview.php file.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47919

Affected Products

Simple-Cms