VendorsOpenSource-WorkShopconnect-cmsall versions
Vulnerabilities

OpenSource-WorkShop Connect-CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-32276
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
Published 2026-03-23 · Analyzed
8.8EPSS 0.008
CVE-2026-32277
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
Published 2026-03-23 · Analyzed
8.7EPSS 0.004
CVE-2026-32278
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
Published 2026-03-23 · Analyzed
8.2EPSS 0.004
CVE-2026-32300
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
Published 2026-03-23 · Analyzed
8.1EPSS 0.004
CVE-2026-32299
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
Published 2026-03-23 · Analyzed
7.5EPSS 0.005
CVE-2026-32279
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
Published 2026-03-23 · Analyzed
6.8EPSS 0.005