CVE-2026-70650
Deferred Deferred - Pending Action

Stored XSS in GetSimple CMS Community Edition

Vulnerability report for CVE-2026-70650, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
getsimple cms 3.3.22
getsimple cms to 3.3.22 (exc)
getsimple cms_ce 3.3.22

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authenticated stored Cross-Site Scripting (XSS) vulnerability in GetSimple CMS versions 3.3.22 and prior. It exists in the page backup viewer (admin/backup-edit.php). Page fields like keywords, description, menu text, and content are HTML-encoded when saved but decoded again in the backup viewer without proper re-escaping. This allows an authenticated user with editing privileges to inject malicious JavaScript into these fields.

Detection Guidance

Check for suspicious JavaScript in page backups by inspecting the admin/backup-edit.php output for unescaped HTML in keywords, description, menu text, or content fields. Look for encoded payloads like <script> tags or event handlers in saved backups.

Impact Analysis

The injected JavaScript executes in the browser of any administrator who views the page's backup, running in the admin control panel context. This could enable actions like theme editing that might lead to remote code execution. The vulnerability is triggered by a simple read request to the backup viewer and requires no CSRF token.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by enabling unauthorized script execution in admin sessions. If exploited, it may allow attackers to access or manipulate sensitive data within the CMS, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Temporarily disable the backup viewer (admin/backup-edit.php) or restrict access to trusted administrators. Monitor page edits for unusual JavaScript injections. Apply input validation and output escaping until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70650. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart