CVE-2026-27147
GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an attacker to embed malicious JavaScript. When the uploaded SVG file is accessed, the script executes in the browser. This issue does not have a fix at the time of publication.
- Affected products
- Getsimple Cms
- Getsimple-ce Getsimple Cms
- ≤ 3.3.22
- CVSS 4.0
- 6.9 MEDIUM
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.2% (10th percentile)
- Weakness
- CWE-79
- NVD status
- Analyzed
- Published
- 2026-02-20
CVE-2026-27147 at NVD
No indexed exploits for CVE-2026-27147 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-27147 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.