CVE-2018-17835: Get-Simple Getsimple CMS
Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.
Affected products
- Get-Simple Getsimple CMS: version 3.3.15 only
Published 2018-10-01. Last modified 2026-06-17.