opensource-workshop/connect-cms
コネクトCMS用リポジトリ
Activity
- Latest release
- 1mo ago
- Total releases
- 248
- Cadence
- ~daily
- Last 12 months
- 24
Reach
- Stars
- 16
Details
- License
- MIT
- First release
- Jan 06, 2020
| Version | Released | |
|---|---|---|
v2.44.1
patch
|
v2.44.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
v1.44.1
patch
|
v1.44.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
v2.44.0
minor
|
v2.44.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
v1.44.0
minor
| ||
v2.43.0
minor
| ||
v1.43.0
minor
| ||
v2.42.0
minor
| ||
v1.42.0
minor
| ||
v2.41.1
patch
| ||
v1.41.1
patch
| ||
v2.41.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.41.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.40.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.40.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.39.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.39.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.38.1
patch
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.38.1
patch
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.38.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.38.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.37.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.37.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.36.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev |
v2.36.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v1.36.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev |
v1.36.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v2.35.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.35.0
minor
6 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32277
GHSA-cmfh-mpmf-fmq4
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
8.7
/ 10
High
Network
Low
Low
Required
Changed
High
High
None
Security Advisory — Cabinet Plugin (DOM-based XSS)SummaryA DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Affected Versions
Patched Versions
DescriptionIn the Cabinet Plugin list view, DOM-based Cross-Site Scripting (XSS) could occur due to how saved names were rendered. If exploited, arbitrary script could run in the victim's browser, which may lead to unauthorized actions or information theft. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.40.0
v1.41.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
+ 4 more Show less
v2.38.1
v2.39.0
v2.40.0
v2.41.0
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.34.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.34.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.33.1
patch
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.33.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.33.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.32.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.32.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.31.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.31.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
2.30.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.30.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.29.1
patch
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.29.1
patch
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.29.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.29.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.28.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.28.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.27.0.1
patch
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.27.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev |
v2.27.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v1.27.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev |
v1.27.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
v2.26.1
patch
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.26.1
patch
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v2.26.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
v1.26.0
minor
5 CVEs
CVE-2026-32300
GHSA-qr6x-wvxr-8hm9
Mar 23, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Security Advisory — My Page Profile Update (Improper Authorization)SummaryAn improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Affected Versions
Patched Versions
DescriptionIn part of the My Page profile update feature, another user's profile information or password could be modified. If exploited, arbitrary user accounts may be taken over. Exploitation requires that the attacker be able to reach the affected functionality as an authenticated user. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShops thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32299
GHSA-62ch-j6x7-722j
Mar 23, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Security Advisory — Page Content Retrieval (Improper Authorization)SummaryAn improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Affected Versions
Patched Versions
DescriptionIn part of the page content retrieval feature, insufficient authorization checks could allow processing associated with non-public pages to be executed. If exploited, the contents and attachments of non-public pages may be obtained by a third party. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32279
GHSA-jh46-85jr-6ph9
Mar 23, 2026
Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin
6.8
/ 10
Medium
Network
Low
High
None
Changed
High
None
None
Security Advisory — Page Management Plugin (SSRF)SummaryA Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Affected Versions
Patched Versions
DescriptionIn the external page migration feature of the Page Management Plugin, a Server-Side Request Forgery (SSRF) issue could occur. If exploited, it may allow access to internal destinations and could result in information disclosure. Exploitation requires privileges that allow use of the page management screen. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32278
GHSA-mv3p-7p89-wq9p
Mar 23, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
8.2
/ 10
High
Network
High
None
Required
Changed
High
High
Low
Security Advisory — Form Plugin (Stored XSS)SummaryA Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Affected Versions
Patched Versions
DescriptionIn the file field of the Form Plugin, Stored Cross-site Scripting (XSS) could occur. If exploited, arbitrary script could run in an administrator's browser, which may lead to unauthorized actions or information theft. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2026-32276
GHSA-hxqw-6qv7-cqfv
Mar 23, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
Security Advisory — Code Study PluginSummaryAn authenticated user may be able to execute arbitrary code in the Code Study Plugin. Affected Versions
Patched Versions
DescriptionIn the Code Study Plugin, an authenticated user could trigger unintended code execution. If exploited, it may lead to code execution on the server or information disclosure. Users affected by this vulnerability should update to a fixed version. SolutionUpdate to the fixed version. For the 1.x series, update to 1.41.1 or later. For the 2.x series, update to 2.41.1 or later. CreditsOpenSource WorkShop thanks Sho Odagiri (小田切 祥) of GMO Cybersecurity by Ierae, Inc. for reporting this vulnerability. Affected versions
1.20.0
v0.0.1.20200106
v0.0.1.20200216
v0.0.1.20200302
v0.0.1.20200411
v0.0.1.20200510
v0.0.1.20200603
v0.0.1.20200716
v0.0.1.20200909
v0.0.1.20201008
v0.0.1.20201207
v0.0.1.20210104
+ 226 more Show less
v0.0.1.20210301
v0.0.1.20210405
v0.0.1.20211130
v0.0.1.20220207
v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.12.1
v1.12.2
v1.12.3
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.16.0
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.17.4
v1.18.0
v1.18.1
v1.18.2
v1.18.3
v1.19.0
v1.19.1
v1.19.2
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.21.0
v1.22.0
v1.23.0
v1.23.1
v1.23.2
v1.23.3
v1.24.0
v1.25.0
v1.25.1
v1.26.0
v1.26.1
v1.27.0
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.30.0
v1.31.0
v1.32.0
v1.33.0
v1.33.1
v1.34.0
v1.35.0
v1.36.0
v1.37.0
v1.38.0
v1.38.1
v1.39.0
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.40.0
v1.41.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.9.0
v1.9.1
v1.9.10
v1.9.11
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
2.30.0
v2.0.0
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.10.0
v2.10.1
v2.10.2
v2.15.0
v2.15.1
v2.15.2
v2.15.3
v2.15.4
v2.16.0
v2.17.0
v2.17.1
v2.17.2
v2.17.3
v2.17.4
v2.18.0
v2.18.1
v2.18.2
v2.18.3
v2.19.0
v2.19.2.1
v2.2.0
v2.2.1
v2.2.2
v2.21.0
v2.22.0
v2.23.0
v2.23.2
v2.23.3
v2.24.0
v2.25.0
v2.25.1
v2.26.0
v2.26.1
v2.27.0
v2.27.0.1
v2.28.0
v2.29.0
v2.29.1
v2.3.0
v2.3.1
v2.3.2
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.36.0
v2.37.0
v2.38.0
v2.38.1
v2.39.0
v2.4.0
v2.4.1
v2.4.10
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.40.0
v2.41.0
v2.5.0
v2.5.1
v2.5.10
v2.5.11
v2.5.2
v2.5.3
v2.5.4
v2.5.5
v2.5.6
v2.5.7
v2.5.8
v2.5.9
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.6.4
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.8.1
v2.8.2
v2.8.3
v2.9.0
v2.9.1
Fixed in
1.41.1
2.41.1
References
Updated Mar 25, 2026 · Source: OSV.dev |