GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在 3.3.22 及更早版本中,GetSimple CMS CE 的“主题到组件”功能(admin/components.php)中存在存储型跨站脚本攻击(Stored XSS)漏洞,该漏洞可通过 参数触发。 存储的标题值会在管理界面中通过一个输出路径进行渲染,该路径在打印前会对值执行 HTML 实体解码,但未针对属性上下文重新进行编码。由于该标题被渲染在双引号包裹的 HTML 属性中,攻击者可在管理面
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE | <= 3.3.22 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE | <= 3.3.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56662 | 9.6 CRITICAL | GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side |
| CVE-2026-53953 | 9.1 CRITICAL | GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover |
| CVE-2026-56660 | 9.1 CRITICAL | GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction |
| CVE-2026-70650 | 8.8 HIGH | GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco |
| CVE-2026-56661 | 7.5 HIGH | GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint |
| CVE-2026-71426 | 7.1 HIGH | GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field |
No comments yet