Sploitus

CVE-2026-27147

No indexed exploits for CVE-2026-27147 yet

GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an attacker to embed malicious JavaScript. When the uploaded SVG file is accessed, the script executes in the browser. This issue does not have a fix at the time of publication.

Affected products
Getsimple Cms
Getsimple-ce Getsimple Cms
≤ 3.3.22
CVSS 4.0
6.9 MEDIUM
CVSS 3.1
5.4 MEDIUM
EPSS
0.2% (10th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2026-02-20
CVE-2026-27147 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-27147 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-27147 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.