Sploitus

CVE-2021-47870

No indexed exploits for CVE-2021-47870 yet

GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to inject arbitrary client-side code that executes in the administrator's browser when visiting a malicious page.

Get-simple Getsimplecms
= 1.1.2
CVSS 3.1
5.4 MEDIUM
EPSS
0.2% (15th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2026-01-21
CVE-2021-47870 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2021-47870 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2021-47870 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.