CVE-2026-71542: GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/components.php
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is rendered inside a double-quoted HTML attribute in the administrative interface through an output path that HTML-entity-decodes the value before printing it, without re-encoding for the attribute context. This allows persistent execution of arbitrary JavaScript in the admin panel. At time of publication, there are no publicly available patches.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs the ability to submit a crafted title through the administrative Theme to Components functionality. The payload is then stored and can execute when the affected administrative interface renders it.
Which deployments are affected?
GetSimpleCMS-CE versions 3.3.22 and earlier are affected. The available information does not state whether the vulnerable functionality is enabled or reachable in a default installation.
What can be done if patching is not immediately possible?
No publicly available patch exists at the time of publication. Restrict access to the administrative interface and, where possible, prevent untrusted users from creating or modifying component titles; review existing stored titles for suspicious content.
How can administrators check for exposure?
Review titles saved through the Theme to Components function, particularly values containing HTML attribute-breaking characters or script-like content. The affected rendering path is in admin/components.php, where stored titles are displayed in an administrative HTML attribute.