CVE-2021-47870
GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to inject arbitrary client-side code that executes in the administrator's browser when visiting a malicious page.
- Affected products
- My Smtp Contact Plugin, Getsimple Cms
- Get-simple Getsimplecms
- = 1.1.2
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2026-01-21
CVE-2021-47870 at NVD
No indexed exploits for CVE-2021-47870 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-47870 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.