PT-2026-27219 · Opensource Workshop · Connect-Cms

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-32276

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain a patch.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-32276

Affected Products

Connect-Cms