CVE-2021-47919: Simple CMS 2.1 Non-Persistent Cross-Site Scripting via Preview Parameter
Published Feb 1, 2026
·Updated
Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.
Affected Software
2 affected components
Simple CMS Simple CMS
SimplePHPscripts Simple Cms Php=2.1
Event History
Feb 1, 2026
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-47919?
CVE-2021-47919 has a medium severity rating due to its potential for non-persistent cross-site scripting attacks.
2
How do I fix CVE-2021-47919?
To fix CVE-2021-47919, validate and sanitize the input of the id parameter in the preview.php file.
3
Can CVE-2021-47919 be exploited remotely?
Yes, CVE-2021-47919 can be exploited remotely via crafted GET requests containing malicious scripts.
4
What software is affected by CVE-2021-47919?
CVE-2021-47919 affects Simple CMS version 2.1.
5
What type of attack is associated with CVE-2021-47919?
CVE-2021-47919 is associated with non-persistent cross-site scripting attacks.