CVE-2026-70650: GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / stripdecode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is at risk from the payload?
An authenticated user who can edit a page can store JavaScript in the page's Keywords, Description, Menu text, or Content fields. The payload executes when an administrator views that page's backup in the admin control panel.
Is the normal page-saving process sufficient to prevent exploitation?
No. The affected fields are HTML-encoded when saved, but the backup viewer decodes them and outputs the decoded values without re-escaping them.
What can be done if patching is not immediately possible?
No publicly available patches exist at the time of publication. Limit page-editing privileges to trusted users and avoid viewing page backups in admin/backup-edit.php for pages that may have been edited by untrusted users.
How can administrators identify potentially affected content?
Review pages editable by untrusted users, especially their Keywords, Description, Menu text, and Content fields, before opening their backups. Stored script content in those fields may execute when the corresponding backup is viewed.