CVE-2026-70650: GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content

Published Oct 1, 2026
·
Updated

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / stripdecode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.

Affected Software

1 affected component
GetSimple CMS GetSimple CMS CE<=3.3.22

Event History

Oct 1, 2026
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who is at risk from the payload?

An authenticated user who can edit a page can store JavaScript in the page's Keywords, Description, Menu text, or Content fields. The payload executes when an administrator views that page's backup in the admin control panel.

2

Is the normal page-saving process sufficient to prevent exploitation?

No. The affected fields are HTML-encoded when saved, but the backup viewer decodes them and outputs the decoded values without re-escaping them.

3

What can be done if patching is not immediately possible?

No publicly available patches exist at the time of publication. Limit page-editing privileges to trusted users and avoid viewing page backups in admin/backup-edit.php for pages that may have been edited by untrusted users.

4

How can administrators identify potentially affected content?

Review pages editable by untrusted users, especially their Keywords, Description, Menu text, and Content fields, before opening their backups. Stored script content in those fields may execute when the corresponding backup is viewed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203