VYPR

Getsimplecms Ce

by Getsimplecms Ce

CVEs (53)

  • CVE-2021-29400MedAug 10, 2021
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.

  • CVE-2021-36601MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.01

    GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: "siteURL" parameter.

  • CVE-2020-18660MedJun 23, 2021
    risk 0.40cvss 6.1epss 0.01

    GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

  • CVE-2020-18659MedJun 23, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php

  • CVE-2020-18658MedJun 23, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.

  • CVE-2020-18657MedJun 23, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.

  • CVE-2013-1420MedJan 2, 2020
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to…

  • CVE-2019-9915MedMar 22, 2019
    risk 0.40cvss 6.1epss 0.04

    GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

  • CVE-2018-16325MedSep 1, 2018
    risk 0.40cvss 6.1epss 0.01

    There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.

  • CVE-2017-10673MedJun 29, 2017
    risk 0.40cvss 6.1epss 0.01

    admin/profile.php in GetSimple CMS 3.x has XSS in a name field.

  • CVE-2026-27147MedFeb 21, 2026
    risk 0.35cvss 5.4epss 0.00

    GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an…

  • CVE-2021-47870MedJan 21, 2026
    risk 0.35cvss 5.4epss 0.00

    GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to…

  • CVE-2023-51246MedJan 8, 2024
    risk 0.35cvss 5.4epss 0.00

    A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.

  • CVE-2023-46040MedOct 31, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function.

  • CVE-2020-21353MedAug 6, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.

  • CVE-2020-20391MedJun 23, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.

  • CVE-2020-24861MedOct 1, 2020
    risk 0.35cvss 5.4epss 0.01

    GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page

  • CVE-2019-16333MedSep 15, 2019
    risk 0.35cvss 5.4epss 0.01

    GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.

  • CVE-2018-19845MedDec 31, 2018
    risk 0.35cvss 5.4epss 0.01

    There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.

  • CVE-2014-8723MedMar 17, 2017
    risk 0.35cvss 5.3epss 0.01

    GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.