Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simplephpscripts
Simplephpscripts simple Cms |
|
| Vendors & Products |
Simplephpscripts
Simplephpscripts simple Cms |
Mon, 02 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 01 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks. | |
| Title | Simple CMS 2.1 Non-Persistent Cross-Site Scripting via Preview Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-01T12:15:50.875Z
Updated: 2026-02-02T18:58:59.334Z
Reserved: 2026-02-01T11:24:18.715Z
Link: CVE-2021-47919
Updated: 2026-02-02T18:58:54.484Z
Status : Undergoing Analysis
Published: 2026-02-01T13:15:56.403
Modified: 2026-02-03T16:44:36.630
Link: CVE-2021-47919
No data.