CVE-2020-24861: Get-Simple Getsimple CMS
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
Affected products
- Get-Simple Getsimple CMS: version 3.3.16 only
Published 2020-10-01. Last modified 2026-06-17.