OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-70650

HIGH · CVSS 8.8 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Versions 3.3.22 and earlier of GetSimple CMS are vulnerable to an authenticated stored Cross-Site Scripting (XSS) flaw in the backup viewer, allowing users with page editing permissions to inject malicious JavaScript into page metadata. This script executes in the browser of any administrator who accesses the backup, potentially compromising the admin control panel. Organizations using this CMS should prioritize remediation due to the high severity of the vulnerability and the lack of available patches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-70650
Severity
HIGH
CVSS
8.8
EPSS
0.26%
Java

Original NVD Description

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches.