216.73.216.123

CVE-2026-27147

· Published 21/02/2026 00:16 · Modified 21/02/2026 00:16

Labels: CVE-2026-27147 2026-02-21CVE-2026-27147CWE-79[email protected]

Essential information

Published
21/02/2026 00:16
Modified
21/02/2026 00:16
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an attacker to embed malicious JavaScript. When the uploaded SVG file is accessed, the script executes in the browser. This issue does not have a fix at the time of publication.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
getsimple / getsimple cms cpe:2.3:a:getsimple:getsimple_cms:*:*:*:*:*:*:*:*

References