CVE-2026-26351: GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php

Published Feb 24, 2026
·
Updated

GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input provided to the "slug" field of a component is stored without proper output encoding. While other fields are sanitized using safeslashhtml(), the slug parameter is written to XML and later rendered in the administrative interface without sanitation, resulting in persistent execution of arbitrary JavaScript. An authenticated administrator can inject malicious script content that executes whenever the affected Components page is viewed by any authenticated user, enabling session hijacking, unauthorized administrative actions, and persistent compromise of the CMS administrative interface.

Affected Software

2 affected components
GetSimpleCMS GetSimpleCMS Community Edition<3.3.22
Getsimple-ce Getsimple Cms>=3.3.16<3.3.22

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GetSimpleCMS Community Edition (CE) to a version that resolves this vulnerability.

    Fixed in 3.3.22
  2. Compensating control

    Restrict access to the CMS administrative interface/components page to trusted authenticated users until the CMS is upgraded to 3.3.22, to limit the impact of the stored XSS.

Event History

Feb 24, 2026
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeaknessAffected Software
Oct 18, 58128
Event
via FIRST·02:07 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-26351?

CVE-2026-26351 has a severity rating that indicates a moderate risk to applications using GetSimpleCMS Community Edition version 3.3.16.

2

How do I fix CVE-2026-26351?

To fix CVE-2026-26351, update to the latest version of GetSimpleCMS Community Edition that addresses the stored XSS vulnerability.

3

What types of inputs are affected by CVE-2026-26351?

CVE-2026-26351 is specifically affected by user-supplied input in the 'slug' field of components in GetSimpleCMS.

4

What does CVE-2026-26351 allow an attacker to do?

CVE-2026-26351 allows an attacker to inject malicious scripts through the Theme to Components functionality, leading to stored cross-site scripting attacks.

5

Which version of GetSimpleCMS is impacted by CVE-2026-26351?

CVE-2026-26351 impacts GetSimpleCMS Community Edition version 3.3.16 and earlier versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203