PKSA-2kyx-vx1v-bbq2 Security Advisory
-
[HIGH] Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
PKSA-2kyx-vx1v-bbq2 CVE-2026-32278 GHSA-mv3p-7p89-wq9p
Affected package: opensource-workshop/connect-cms
Affected version: >=2.0.0,<=2.41.0|<=1.41.0
Reported by:
GitHub