CVE-2026-27147Disclosure(getsimple-ce / getsimple_cms)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an attacker to embed malicious JavaScript. When the uploaded SVG file is accessed, the script executes in the browser. This issue does not have a fix at the time of publication.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • getsimple_cms

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
getsimple_cms

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-20: 1Mentions · 2026-02-22: 1Mentions · 2026-03-07: 1PoC Mentioned / Linked · 2026-02-22: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-22: 1Technical Details · 2026-03-07: 102-2002-2203-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Antony Esthak Twinson@Twinson_333
    Disclosure

    How I discovered CVE-2026–27147 — Stored XSS | Cyber Tamarin https://medium.com/p/how-i-discovered-cve-2026-27147-stored-xss-cyber-tamarin-c5ff993a3062?source=social.tw

    Post summary

    The Medium post announces the discovery of CVE‑2026‑27147, a stored XSS flaw, but does not provide a PoC, exploit code, active exploitation reports, or patch information.

    0000034
    6 followersView on X
  • One_Plate_IDLY@NO_ChutneyPLZ
    Disclosure

    https://cybertamarin.medium.com/how-i-discovered-cve-2026-27147-stored-xss-cyber-tamarin-c5ff993a3062

    Post summary

    The Medium article reports the discovery of CVE-2026-27147, a stored XSS vulnerability, providing technical details and a PoC, but does not mention active exploitation, patches, or false positives.

    0000042
    51 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27147 GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files v… https://www.cve.org/CVERecord?id=CVE-2026-27147

    Post summary

    CVE-2026-27147 affects all GetSimple CMS versions, allowing XSS via authenticated SVG file uploads; no PoC, exploit, active exploitation, or patch details are provided.

    0000047
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetsimple-cegetsimple_cms---

Explore more