CVE-2026-71542: GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/components.php

Published Oct 1, 2026
·
Updated

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches.

Affected Software

1 affected component
GetSimple CMS GetSimple CMS CE<=3.3.22

Event History

Oct 1, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs the ability to submit a crafted title through the administrative Theme to Components functionality. The payload is then stored and can execute when the affected administrative interface renders it.

2

Which deployments are affected?

GetSimpleCMS-CE versions 3.3.22 and earlier are affected. The available information does not state whether the vulnerable functionality is enabled or reachable in a default installation.

3

What can be done if patching is not immediately possible?

No publicly available patch exists at the time of publication. Restrict access to the administrative interface and, where possible, prevent untrusted users from creating or modifying component titles; review existing stored titles for suspicious content.

4

How can administrators check for exposure?

Review titles saved through the Theme to Components function, particularly values containing HTML attribute-breaking characters or script-like content. The affected rendering path is in admin/components.php, where stored titles are displayed in an administrative HTML attribute.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203