opensource-workshop/connect-cms
Packagist4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting opensource-workshop/connect-cmspage 1 of 1
- CVE-2026-32278MEDIUMCVSS 4.8EG 4.8✓ Fixed in 1.41.12026-03-23
vulnerable: 1.20.0 ... v1.9.9 (137 versions)
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form …
- CVE-2026-32279MEDIUMCVSS 6.8EG 6.8✓ Fixed in 1.41.12026-03-23
vulnerable: 1.20.0 ... v1.9.9 (137 versions)
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Request Forgery (SSRF) issue exists in the external page migratio…
- CVE-2026-32299HIGHCVSS 7.5EG 7.5✓ Fixed in 1.41.12026-03-23
vulnerable: 1.20.0 ... v1.9.9 (137 versions)
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow…
- CVE-2026-32300HIGHCVSS 8.1EG 8.1✓ Fixed in 1.41.12026-03-23
vulnerable: 1.20.0 ... v1.9.9 (137 versions)
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow…
Check whether opensource-workshop/connect-cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for opensource-workshop/connect-cms CVEs against the assets you own.
Start Free Scan →