Vendorsget-simplegetsimple_cms3.3.16
Vulnerabilities

get-simple GetSimple CMS 3.3.16

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-41544
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.
Published 2022-10-18 · Modified
9.81 PoCEPSS 0.108
CVE-2020-23839
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials, and submits the login form.
Published 2020-09-01 · Modified
6.11 PoCEPSS 0.105
CVE-2020-24861
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
Published 2020-10-01 · Modified
5.4EPSS 0.009