CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that executes when users click on Page or Files tabs, enabling persistent script injection.
References
| Link | Resource |
|---|---|
| https://www.cmsimple.org/en/ | Product |
| https://www.exploit-db.com/exploits/49751 | Exploit |
| https://www.vulncheck.com/advisories/cmsimple-stored-cross-site-scripting-via-filebrowser-external-input | Third Party Advisory |
Configurations
History
05 Jan 2026, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
31 Dec 2025, 21:43
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Cmsimple
Cmsimple cmsimple |
|
| CPE | cpe:2.3:a:cmsimple:cmsimple:5.2:*:*:*:*:*:*:* | |
| References | () https://www.cmsimple.org/en/ - Product | |
| References | () https://www.exploit-db.com/exploits/49751 - Exploit | |
| References | () https://www.vulncheck.com/advisories/cmsimple-stored-cross-site-scripting-via-filebrowser-external-input - Third Party Advisory |
23 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-23 20:15
Updated : 2026-01-05 14:15
NVD link : CVE-2021-47732
Mitre link : CVE-2021-47732
CVE.ORG link : CVE-2021-47732
JSON object : View
Products Affected
cmsimple
- cmsimple
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
