Junglewise Threat Intelligence

CVE-2026-26351: GetSimpleCMS CE stored XSS in components.php slug field

CVE-2026-26351 · Severity: medium · CVSS 4.8 · Published 2026-02-24

Executive brief

GetSimpleCMS Community Edition, a lightweight system for managing website content, is vulnerable to a security flaw where malicious scripts can be permanently stored on the server. An attacker with administrative access can inject these scripts into specific configuration fields, which then execute when other administrators view the management console. This could lead to unauthorized actions, session hijacking, or full compromise of the website's administrative interface.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GetSimpleCMS CE versions prior to 3.3.22 within the 'Theme to Components' functionality (components.php). The vulnerability is caused by a lack of output encoding on the 'slug' parameter; while other fields utilize the safe_slash_html() sanitization function, the slug is written directly to XML and subsequently rendered in the admin UI without neutralization. An authenticated attacker with high privileges can inject arbitrary JavaScript into this field. The payload executes in the context of any user who views the affected Components page, allowing for session token theft and persistent administrative interface compromise. The issue is addressed in version 3.3.22.

Affected products

  • GetSimpleCMS-CE GetSimpleCMS Community Edition (CE) versions prior to 3.3.22

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: advisory
  • 2026-06-15: patched: Version 3.3.22 released

References