VYPR

Getsimplecms Ce

by Getsimplecms Ce

CVEs (53)

  • CVE-2021-47860MedJan 21, 2026
    risk 0.34cvss 5.3epss 0.00

    GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrator browsers. Attackers can craft a malicious website that triggers a cross-site scripting payload to…

  • CVE-2026-26351MedFeb 24, 2026
    risk 0.31cvss 4.8epss 0.00

    GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input provided to the "slug" field of a component is stored…

  • CVE-2023-6188MedNov 17, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2020-20389MedJun 23, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.

  • CVE-2021-28977MedJun 23, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,

  • CVE-2018-15843MedAug 25, 2018
    risk 0.31cvss 4.8epss 0.01

    GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.

  • CVE-2026-27146MedFeb 21, 2026
    risk 0.29cvss 4.5epss 0.00

    GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload request from an authenticated…

  • CVE-2024-11125MedNov 12, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed…

  • CVE-2018-19421LowNov 21, 2018
    risk 0.25cvss 3.8epss 0.01

    In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.

  • CVE-2018-19420LowNov 21, 2018
    risk 0.25cvss 3.8epss 0.01

    In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upload-uploadify.php, and…

  • CVE-2022-1503LowApr 27, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like leads to cross site…

  • CVE-2015-5356Jul 1, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the func parameter.

  • CVE-2015-5355Jul 1, 2015
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post-content or (2) post-title parameter to admin/edit.php.

Page 3 of 3