CVE-2021-47733
EUVD-2025-20482223.12.2025, 20:15
CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attackers can inject malicious scripts by encoding payloads like ')-alert(1)// and execute arbitrary JavaScript when victims interact with delete buttons.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cmsimple | cmsimple | 5.4 |
𝑥
= Vulnerable software versions