CVE-2026-70650 – GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content

​CVE ID :CVE-2026-70650

Published : Oct. 1, 2026, 8:17 p.m. | 1 hour, 4 minutes ago

Description :GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page’s Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page’s backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More