Getsimplecms Ce
CVEs (53)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-29400 | Med | 0.42 | 6.5 | 0.01 | Aug 10, 2021 | A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site. | ||
| CVE-2021-36601 | Med | 0.40 | 6.1 | 0.01 | Aug 10, 2021 | GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: "siteURL" parameter. | ||
| CVE-2020-18660 | Med | 0.40 | 6.1 | 0.01 | Jun 23, 2021 | GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter. | ||
| CVE-2020-18659 | Med | 0.40 | 6.1 | 0.01 | Jun 23, 2021 | Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php | ||
| CVE-2020-18658 | Med | 0.40 | 6.1 | 0.01 | Jun 23, 2021 | Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php. | ||
| CVE-2020-18657 | Med | 0.40 | 6.1 | 0.01 | Jun 23, 2021 | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function. | ||
| CVE-2013-1420 | Med | 0.40 | 6.1 | 0.01 | Jan 2, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to… | ||
| CVE-2019-9915 | Med | 0.40 | 6.1 | 0.04 | Mar 22, 2019 | GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter. | ||
| CVE-2018-16325 | Med | 0.40 | 6.1 | 0.01 | Sep 1, 2018 | There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field. | ||
| CVE-2017-10673 | Med | 0.40 | 6.1 | 0.01 | Jun 29, 2017 | admin/profile.php in GetSimple CMS 3.x has XSS in a name field. | ||
| CVE-2026-27147 | Med | 0.35 | 5.4 | 0.00 | Feb 21, 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an… | ||
| CVE-2021-47870 | Med | 0.35 | 5.4 | 0.00 | Jan 21, 2026 | GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to… | ||
| CVE-2023-51246 | Med | 0.35 | 5.4 | 0.00 | Jan 8, 2024 | A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page. | ||
| CVE-2023-46040 | Med | 0.35 | 5.4 | 0.01 | Oct 31, 2023 | Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function. | ||
| CVE-2020-21353 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2021 | A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module. | ||
| CVE-2020-20391 | Med | 0.35 | 5.4 | 0.01 | Jun 23, 2021 | Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets. | ||
| CVE-2020-24861 | Med | 0.35 | 5.4 | 0.01 | Oct 1, 2020 | GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page | ||
| CVE-2019-16333 | Med | 0.35 | 5.4 | 0.01 | Sep 15, 2019 | GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php. | ||
| CVE-2018-19845 | Med | 0.35 | 5.4 | 0.01 | Dec 31, 2018 | There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325. | ||
| CVE-2014-8723 | Med | 0.35 | 5.3 | 0.01 | Mar 17, 2017 | GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message. |
- risk 0.42cvss 6.5epss 0.01
A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
- risk 0.40cvss 6.1epss 0.01
GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: "siteURL" parameter.
- risk 0.40cvss 6.1epss 0.01
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
- risk 0.40cvss 6.1epss 0.01
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.
- risk 0.40cvss 6.1epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to…
- risk 0.40cvss 6.1epss 0.04
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
- risk 0.40cvss 6.1epss 0.01
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
- risk 0.40cvss 6.1epss 0.01
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
- risk 0.35cvss 5.4epss 0.00
GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an…
- risk 0.35cvss 5.4epss 0.00
GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to…
- risk 0.35cvss 5.4epss 0.00
A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function.
- risk 0.35cvss 5.4epss 0.01
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.
- risk 0.35cvss 5.4epss 0.01
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
- risk 0.35cvss 5.4epss 0.01
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
- risk 0.35cvss 5.4epss 0.01
There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.
- risk 0.35cvss 5.3epss 0.01
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.
Page 2 of 3