CVE-2026-32277 - Vulnerability Analysis
HighCVSS: 8.7Last Updated: March 23, 2026
Connect-CMS - Stored XSS
Overview
Connect-CMS 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0 contain a stored XSS caused by improper sanitization in the Cabinet Plugin list view, letting attackers execute scripts in victim browsers, exploit requires victim interaction.
Severity & Score
Impact
Attackers can execute scripts in users' browsers, potentially stealing cookies or performing actions on behalf of users.
Mitigation
Update to versions 1.41.1 or 2.41.1 or later.
References
- https://github.com/opensource-workshop/connect-cms/commit/c04dc40f814eff891915752ef1ec00ba6612441c
- https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1
- https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1
- https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-cmfh-mpmf-fmq4
Social Media Activity(4 posts)
š CVE-2026-32277 - High (8.7) Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch. š https://www.thehackerwire.com/vulnerability/CVE-2026-32277/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-32277 - High (8.7) Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch. š https://www.thehackerwire.com/vulnerability/CVE-2026-32277/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-32277 - High (8.7) Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch. š https://www.thehackerwire.com/vulnerability/CVE-2026-32277/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-32277 - High (8.7) Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch. š https://www.thehackerwire.com/vulnerability/CVE-2026-32277/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-32277
- Severity
- High
- CVSS Score
- 8.7
- Type
- stored_xss
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 4
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N