Home/Product/get simple getsimple cms
Product

get simple getsimple cms

59 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-28495
<= 3.3.22
GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an auth
9.6CRITICAL
CVE-2026-26351
>= 3.3.16 and < 3.3.22
GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS) vulnerab
4.8MEDIUM
CVE-2026-27202
all versions
GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows
7.5HIGH
CVE-2026-27161
<= 3.3.22
GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitiv
7.5HIGH
CVE-2026-27147
<= 3.3.22
GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authen
5.4MEDIUM
CVE-2026-27146
<= 3.3.22
GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative
4.5MEDIUM
CVE-2021-47870
all versions
GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to
5.4MEDIUM
CVE-2021-47860
all versions
GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to in
5.3MEDIUM
CVE-2021-47830
all versions
GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malic
6.5MEDIUM
CVE-2021-47778
all versions
GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject
7.2HIGH
CVE-2013-10032
all versions
An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint
8.8HIGH
CVE-2025-48492
>= 3.3.16 and < 3.3.22
GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the
8.8HIGH
CVE-2024-55088
all versions
GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.
8.8HIGH
CVE-2024-55086
all versions
In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address
7.2HIGH
CVE-2024-55085
all versions
GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system
9.8CRITICAL
CVE-2024-11125
all versions
A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the
4.3MEDIUM
CVE-2023-51246
all versions
A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add art
5.4MEDIUM
CVE-2023-6188
all versions
A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing
4.7MEDIUM
CVE-2023-46040
all versions
Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted p
5.4MEDIUM
CVE-2023-46042
all versions
An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().
9.8CRITICAL
CVE-2022-41544
all versions
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin
9.8CRITICAL
CVE-2022-1503
all versions
A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/e
3.5LOW
CVE-2021-36601
all versions
GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Web
6.1MEDIUM
CVE-2020-21353
all versions
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbit
5.4MEDIUM
CVE-2020-18660
<= 3.3.15
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
6.1MEDIUM
CVE-2020-18659
<= 3.3.15
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin
6.1MEDIUM
CVE-2020-18658
<= 3.3.15
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
6.1MEDIUM
CVE-2020-18657
<= 3.3.15
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the
6.1MEDIUM
CVE-2020-20391
all versions
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.
5.4MEDIUM
CVE-2020-20389
all versions
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.
4.8MEDIUM
CVE-2021-28977
<= 3.3.15
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header info
4.8MEDIUM
CVE-2021-28976
< 3.3.15
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
7.2HIGH
CVE-2020-18191
all versions
GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.
9.1CRITICAL
CVE-2020-24861
all versions
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when y
5.4MEDIUM
CVE-2020-23839
all versions
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows
6.1MEDIUM
CVE-2013-1420
< 3.2.1
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web s
6.1MEDIUM
CVE-2019-16333
all versions
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
5.4MEDIUM
CVE-2019-11231
<= 3.3.15
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of
9.8CRITICAL
CVE-2019-9915
all versions
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
6.1MEDIUM
CVE-2018-19845
all versions
There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.
5.4MEDIUM
CVE-2018-19421
all versions
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because o
3.8LOW
CVE-2018-19420
all versions
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be execute
3.8LOW
CVE-2018-17835
all versions
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalin
4.8MEDIUM
CVE-2018-17103
all versions
An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via a
8.8HIGH
CVE-2018-16325
all versions
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
6.1MEDIUM
CVE-2018-15843
all versions
GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
4.8MEDIUM
CVE-2018-9173
all versions
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attack
6.1MEDIUM
CVE-2017-10673
all versions
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
6.1MEDIUM
CVE-2017-8081
all versions
Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to es
8.8HIGH
CVE-2014-8723
all versions
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php
5.3MEDIUM
CVE-2014-8722
all versions
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml,
7.5HIGH
CVE-2015-5356
<= 3.3.2
Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject
CVE-2015-5355
<= 3.3.2
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web s
CVE-2014-8790
all versions
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain
CVE-2014-1603
all versions
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script o
CVE-2013-7243
all versions
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1.2 and 3.2.3 allow remote attackers to inject arbitrary we
CVE-2012-6621
<= 3.2.3
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1, 3.1.2, 3.2.3, and earlier allow remote attackers to inje
CVE-2010-5052
all versions
Cross-site scripting (XSS) vulnerability in admin/components.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary
CVE-2010-4863
all versions
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary
threatengine.sh