LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32278

CVE-2026-32278 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: March 23, 2026

Connect-CMS - Stored XSS

Published: March 23, 2026Updated: March 23, 2026Remote Exploitable

Overview

Connect-CMS 1.x <= 1.41.0 and 2.x <= 2.41.0 contain a stored XSS caused by improper sanitization in the file field of the Form Plugin, letting attackers execute scripts in users' browsers, exploit requires user interaction.

Severity & Score

Severity: High
CVSS Score: 8.2
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can execute scripts in users' browsers, potentially stealing data or performing actions on behalf of users.

Mitigation

Update to versions 1.41.1 or 2.41.1 or later.

Social Media Activity(4 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-32278 - High (8.2) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32278/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-32278 - High (8.2) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32278/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-32278 - High (8.2) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32278/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 23, 2026

🟠 CVE-2026-32278 - High (8.2) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32278/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-32278
Severity
High
CVSS Score
8.2
Type
stored_xss
Status
new
EPSS
0.0%
Social Posts
4

CWE

  • CWE-434

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L

EPSS Score

0.0%Probability of exploitation in the next 30 days