All 6 CVE vulnerabilities found in connect-cms, with AI-generated Chinese analysis, references, and POCs.
Vendor: opensource-workshop
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-32300 | Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information CWE-285 | 8.1 | High | 2026-03-23 |
| CVE-2026-32299 | Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature CWE-284 | 7.5 | High | 2026-03-23 |
| CVE-2026-32279 | Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin CWE-918 | 6.8 | Medium | 2026-03-23 |
| CVE-2026-32278 | Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin CWE-434 | 8.2 | High | 2026-03-23 |
| CVE-2026-32277 | Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View CWE-79 | 8.7 | High | 2026-03-23 |
| CVE-2026-32276 | Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin CWE-94 | 8.8 | High | 2026-03-23 |
All 6 known CVE vulnerabilities affecting connect-cms with full Chinese analysis, references, and POCs where available.