CVE-2026-27147 describes a Cross-Site Scripting (XSS) vulnerability affecting all versions of GetSimple CMS, including getsimple_ce and getsimple_cms. Authenticated users can exploit this by uploading unsanitized SVG files containing malicious JavaScript, which executes when the file is accessed. This vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack requiring low privileges and user interaction, with potential for low impact on confidentiality and integrity. Currently, there is no known fix, active exploitation, or publicly available exploit code, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.22CPE matchmatch criteria | cpe:2.3:a:getsimple-ce:getsimple_cms:*:*:*:*:community:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.