VYPR

Packagist (Composer) package

opensource-workshop/connect-cms

pkg:composer/opensource-workshop/connect-cms

Vulnerabilities (6)

  • CVE-2026-32300HigMar 23, 2026
    affected < 1.41.1fixed 1.41.1

    Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user informati

  • CVE-2026-32299HigMar 23, 2026
    affected < 1.41.1fixed 1.41.1

    Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Ver

  • CVE-2026-32279MedMar 23, 2026
    affected < 1.41.1fixed 1.41.1

    Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin.

  • CVE-2026-32278HigMar 23, 2026
    affected < 1.41.1fixed 1.41.1

    Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Versions 1.41.1 and 2.41.1 contai

  • CVE-2026-32277HigMar 23, 2026
    affected >= 1.35.0, < 1.41.1fixed 1.41.1

    Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch.

  • CVE-2026-32276HigMar 23, 2026
    affected < 1.41.1fixed 1.41.1

    Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain