CVE-2026-70650

Source
https://cve.org/CVERecord?id=CVE-2026-70650
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70650.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-70650
Aliases
  • GHSA-p6vf-2xr7-mcf4
Published
2026-10-01T19:39:00Z
Modified
2026-10-03T03:30:48Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output decoding of page meta fields and content
Details

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70650.json"
}
References

Affected packages

Git / github.com/getsimplecms-ce/getsimplecms-ce

Affected ranges

Type
GIT
Repo
https://github.com/getsimplecms-ce/getsimplecms-ce
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "3.3.22"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v3.*
v3.3.16
v3.3.17
v3.3.18.1
v3.3.21
v3.3.22

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70650.json"