CVE-2026-32278 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: March 23, 2026
Connect-CMS - Stored XSS
Overview
Connect-CMS 1.x <= 1.41.0 and 2.x <= 2.41.0 contain a stored XSS caused by improper sanitization in the file field of the Form Plugin, letting attackers execute scripts in users' browsers, exploit requires user interaction.
Severity & Score
Impact
Attackers can execute scripts in users' browsers, potentially stealing data or performing actions on behalf of users.
Mitigation
Update to versions 1.41.1 or 2.41.1 or later.
References
- https://github.com/opensource-workshop/connect-cms/commit/9d87fe8ecf7f57efbb0e5231be058807734c96b3
- https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1
- https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1
- https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-mv3p-7p89-wq9p
Social Media Activity(4 posts)
š CVE-2026-32278 - High (8.2) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. ... š https://www.thehackerwire.com/vulnerability/CVE-2026-32278/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-32278 - High (8.2) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. ... š https://www.thehackerwire.com/vulnerability/CVE-2026-32278/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-32278 - High (8.2) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. ... š https://www.thehackerwire.com/vulnerability/CVE-2026-32278/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-32278 - High (8.2) Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. ... š https://www.thehackerwire.com/vulnerability/CVE-2026-32278/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-32278
- Severity
- High
- CVSS Score
- 8.2
- Type
- stored_xss
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 4
CWE
- CWE-434
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L