CVE-2026-71542 – GetSimple CMS: Stored Cross-Site Scripting (XSS) via the “title” parameter in admin/components.php

​CVE ID :CVE-2026-71542

Published : Oct. 1, 2026, 8:17 p.m. | 1 hour, 4 minutes ago

Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the “Theme to Components” functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More