CVE-2026-27147 MEDIUM

CVE-2026-27147: GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated)

Vendor Getsimplecms-Ce
Product GetSimpleCMS-CE
Weakness CWE-79 · XSS
Published February 20, 2026
Last update February 25, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an attacker to embed malicious JavaScript. When the uploaded SVG file is accessed, the script executes in the browser. This issue does not have a fix at the time of publication.

Key dates

02Disclosure timeline

February 20, 2026 CVE published
February 25, 2026 Record updated

Related vulnerabilities

04Related CVE