Medium severity6.4NVD Advisory· Published Feb 1, 2026· Updated Jun 17, 2026
CVE-2021-47919
CVE-2021-47919
Description
Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:simplephpscripts:simple_cms_php:2.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:simplephpscripts:simple_cms_php:2.1:*:*:*:*:*:*:*
- (no CPE)range: 2.1
- Range: = 2.1
Patches
Vulnerability mechanics
References
3- www.vulnerability-lab.com/get_content.phpnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/simple-cms-non-persistent-cross-site-scripting-via-preview-parameternvdThird Party Advisory
- simplephpscripts.com/simple-cms-phpnvdProduct
News mentions
0No linked articles in our index yet.