Vulnerability Details CVE-2026-32277
Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.8%
CVSS Severity
CVSS v3 Score 8.7
Products affected by CVE-2026-32277
-
cpe:2.3:a:opensource-workshop:connect-cms:1.35.0
-
cpe:2.3:a:opensource-workshop:connect-cms:1.36.0
-
cpe:2.3:a:opensource-workshop:connect-cms:1.37.0
-
cpe:2.3:a:opensource-workshop:connect-cms:1.38.0
-
cpe:2.3:a:opensource-workshop:connect-cms:1.38.1
-
cpe:2.3:a:opensource-workshop:connect-cms:1.39.0
-
cpe:2.3:a:opensource-workshop:connect-cms:1.40.0
-
cpe:2.3:a:opensource-workshop:connect-cms:1.41.0
-
cpe:2.3:a:opensource-workshop:connect-cms:2.35.0
-
cpe:2.3:a:opensource-workshop:connect-cms:2.36.0
-
cpe:2.3:a:opensource-workshop:connect-cms:2.37.0
-
cpe:2.3:a:opensource-workshop:connect-cms:2.38.0
-
cpe:2.3:a:opensource-workshop:connect-cms:2.38.1
-
cpe:2.3:a:opensource-workshop:connect-cms:2.39.0
-
cpe:2.3:a:opensource-workshop:connect-cms:2.40.0
-
cpe:2.3:a:opensource-workshop:connect-cms:2.41.0