
CVE-2026-32277 · NIST 8.7/10 https://nvd.nist.gov/vuln/detail/CVE-2026-32277
Post summary
The post points to CVE-2026-32277 with a high NIST CVSS rating but offers no additional technical, exploit, or mitigation details.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-03-23 | 2 | Disclosure1Patch1 |
| 2026-03-24 | 1 | General1 |
| 2026-04-07 | 1 | General1 |

CVE-2026-32277 · NIST 8.7/10 https://nvd.nist.gov/vuln/detail/CVE-2026-32277
Post summary
The post points to CVE-2026-32277 with a high NIST CVSS rating but offers no additional technical, exploit, or mitigation details.

CVE-2026-32277 DOM-Based Cross-Site Scripting in Connect-CMS Cabinet Plugin List View https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32277
Post summary
The post gives a brief description of a DOM‑based XSS in Connect‑CMS but lacks any PoC, exploit code, active exploitation, or patch details.

🟠 CVE-2026-32277 - High Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. V... https://www.thehackerwire.com/vulnerability/CVE-2026-32277/ https://t.co/OefEXssFci
Post summary
The post discloses CVE-2026‑32277, a high‑severity DOM‑based XSS vulnerability in Connect‑CMS Cabinet Plugin list view for specific version ranges.

[CVE-2026-32277: HIGH] Critical security update for Connect-CMS! Versions 1.35.0 to 1.41.0 and 2.35.0 to 2.41.0 affected by DOM-based XSS. Update to patched versions 1.41.1 and 2.41.1 now. #cybersecurity#cve,CVE-2026-32277,#cybersecurity https://cvefind.com/CVE-2026-32277
Post summary
The post reports a critical DOM‑based XSS in Connect‑CMS and directs users to upgrade to the patched versions 1.41.1 and 2.41.1.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | opensource-workshop | connect-cms | - | - | - |