CVE-2020-24861: Get-Simple Getsimple CMS

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page

Affected products

Published 2020-10-01. Last modified 2026-06-17.