Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 06 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:get-simple:getsimplecms:0.1:*:*:*:*:*:*:* |
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getsimple-ce
Getsimple-ce getsimple Cms |
|
| CPEs | cpe:2.3:a:getsimple-ce:getsimple_cms:0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Getsimple-ce
Getsimple-ce getsimple Cms |
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Get-simple
Get-simple getsimplecms |
|
| Vendors & Products |
Get-simple
Get-simple getsimplecms |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrator browsers. Attackers can craft a malicious website that triggers a cross-site scripting payload to execute remote code on the hosting server when an authenticated administrator visits the page. | |
| Title | GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:06:20.133Z
Reserved: 2026-01-18T12:35:05.169Z
Link: CVE-2021-47860
Updated: 2026-01-22T16:48:14.805Z
Status : Analyzed
Published: 2026-01-21T18:16:17.100
Modified: 2026-03-06T20:10:32.250
Link: CVE-2021-47860
No data.
OpenCVE Enrichment
Updated: 2026-01-22T10:09:01Z