VYPR

Getsimplecms

by Get Simple.

Source repositories

CVEs (48)

  • CVE-2017-10673MedJun 29, 2017
    risk 0.40cvss 6.1epss 0.01

    admin/profile.php in GetSimple CMS 3.x has XSS in a name field.

  • CVE-2021-47870MedJan 21, 2026
    risk 0.35cvss 5.4epss 0.00

    GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to…

  • CVE-2023-51246MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.

  • CVE-2023-46040MedOct 31, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function.

  • CVE-2020-21353MedAug 6, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.

  • CVE-2020-20391MedJun 23, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.

  • CVE-2020-24861MedOct 1, 2020
    risk 0.35cvss 5.4epss 0.01

    GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page

  • CVE-2019-16333MedSep 15, 2019
    risk 0.35cvss 5.4epss 0.01

    GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.

  • CVE-2018-19845MedDec 31, 2018
    risk 0.35cvss 5.4epss 0.01

    There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.

  • CVE-2014-8723MedMar 17, 2017
    risk 0.35cvss 5.3epss 0.01

    GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.

  • CVE-2021-47860MedJan 21, 2026
    risk 0.34cvss 5.3epss 0.00

    GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrator browsers. Attackers can craft a malicious website that triggers a cross-site scripting payload to…

  • CVE-2023-6188MedNov 17, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2020-20389MedJun 23, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.

  • CVE-2021-28977MedJun 23, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,

  • CVE-2018-17835MedOct 1, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.

  • CVE-2018-15843MedAug 25, 2018
    risk 0.31cvss 4.8epss 0.01

    GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.

  • CVE-2024-11125MedNov 12, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed…

  • CVE-2018-19421LowNov 21, 2018
    risk 0.25cvss 3.8epss 0.01

    In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.

  • CVE-2018-19420LowNov 21, 2018
    risk 0.25cvss 3.8epss 0.01

    In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upload-uploadify.php, and…

  • CVE-2022-1503LowApr 27, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like leads to cross site…