Unrated severityNVD Advisory· Published Feb 1, 2026· Updated Mar 5, 2026
Simple CMS 2.1 Non-Persistent Cross-Site Scripting via Preview Parameter
CVE-2021-47919
Description
Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.
Affected products
2- Range: =2.1
- Simplephpscripts/Simple CMSv5Range: 2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.vulnerability-lab.com/get_content.phpmitreexploit
- www.vulncheck.com/advisories/simple-cms-non-persistent-cross-site-scripting-via-preview-parametermitrethird-party-advisory
- simplephpscripts.com/simple-cms-phpmitreproduct
News mentions
0No linked articles in our index yet.