Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-71542— GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/components.php

Quick assessment

Affected
GetSimpleCMS-CE GetSimpleCMS-CE
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在 3.3.22 及更早版本中,GetSimple CMS CE 的“主题到组件”功能(admin/components.php)中存在存储型跨站脚本攻击(Stored XSS)漏洞,该漏洞可通过 参数触发。 存储的标题值会在管理界面中通过一个输出路径进行渲染,该路径在打印前会对值执行 HTML 实体解码,但未针对属性上下文重新进行编码。由于该标题被渲染在双引号包裹的 HTML 属性中,攻击者可在管理面

CVSS 8.7 · High EPSS 0.40% · P32

Affected Version Matrix 1

VendorProduct Version RangeStatus
GetSimpleCMS-CE GetSimpleCMS-CE <= 3.3.22 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71542

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/components.php
Source: CVE Program / CVE List V5
Vulnerability Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GetSimpleCMS-CE GetSimpleCMS-CE <= 3.3.22 -

II. Public POCs for CVE-2026-71542

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71542

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-71542 (1)

Same Patch Batch · GetSimpleCMS-CE · 2026-10-01 · 7 CVEs total

CVE-2026-56662 9.6 CRITICAL GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side
CVE-2026-53953 9.1 CRITICAL GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover
CVE-2026-56660 9.1 CRITICAL GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
CVE-2026-70650 8.8 HIGH GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco
CVE-2026-56661 7.5 HIGH GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
CVE-2026-71426 7.1 HIGH GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field

IV. Related Vulnerabilities

V. Comments for CVE-2026-71542

No comments yet


Leave a comment