Connect-CMS is a content management system for easily creating websites.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-32300 opensource-workshop/connect-cms is vulnerable to Improper Authorization in versions 0.0.0 - 1.41.0 and 2.0.0 - 2.41.0. | 0.0.0 - 1.41.02.0.0 - 2.41.0 | High |
CVE-2026-32299 opensource-workshop/connect-cms is vulnerable to Improper Access Control in versions 0.0.0 - 1.40.0 and 2.0.0 - 2.40.0. | 0.0.0 - 1.40.02.0.0 - 2.40.0 | High |
CVE-2026-32279 opensource-workshop/connect-cms is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 1.41.0 and 2.0.0 - 2.41.0. | 0.0.0 - 1.41.02.0.0 - 2.41.0 | Medium |
CVE-2026-32278 opensource-workshop/connect-cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.41.0 and 2.0.0 - 2.41.0. | 0.0.0 - 1.41.02.0.0 - 2.41.0 | High |
CVE-2026-32277 opensource-workshop/connect-cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.35.0 - 1.41.1 and 2.35.0 - 2.41.1. | 1.35.0 - 1.41.12.35.0 - 2.41.1 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ui Version ^4.0 | — | — |
mews/captcha Version 3.3.0 | — | — |
symfony/yaml Version ^5.4 | — | — |
doctrine/dbal Version ^3.0 | — | — |
setasign/fpdi Version ^2.3 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant