Medium severity6.1NVD Advisory· Published Dec 23, 2025· Updated Jun 17, 2026
CVE-2021-47732
CVE-2021-47732
Description
CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that executes when users click on Page or Files tabs, enabling persistent script injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/49751nvdExploit
- www.vulncheck.com/advisories/cmsimple-stored-cross-site-scripting-via-filebrowser-external-inputnvdThird Party Advisory
- www.cmsimple.org/en/nvdProduct
News mentions
0No linked articles in our index yet.