
CVE-2026-30944 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any aut… https://www.cve.org/CVERecord?id=CVE-2026-30944
Post summary
The text mentions CVE-2026-30944 and notes that prior to version 0.4.0 the /studiocms_api/dashboard/api-tokens endpoint is vulnerable, but does not provide any PoC, exploit, patch, or evidence of active exploitation.



