CVE-2026-32277General(opensource-workshop / connect-cms)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch opensource-workshop connect-cms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect-cms

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-23); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
connect-cms

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Mentions · 2026-04-07: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 1Technical Details · 2026-04-07: 103-2303-2404-07
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-232
Disclosure1Patch1
2026-03-241
General1
2026-04-071
General1
Full discourse4 posts
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-32277 · NIST 8.7/10 https://nvd.nist.gov/vuln/detail/CVE-2026-32277

    Post summary

    The post points to CVE-2026-32277 with a high NIST CVSS rating but offers no additional technical, exploit, or mitigation details.

    1000032
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32277 DOM-Based Cross-Site Scripting in Connect-CMS Cabinet Plugin List View https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32277

    Post summary

    The post gives a brief description of a DOM‑based XSS in Connect‑CMS but lacks any PoC, exploit code, active exploitation, or patch details.

    0000033
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32277 - High Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. V... https://www.thehackerwire.com/vulnerability/CVE-2026-32277/ https://t.co/OefEXssFci

    Post summary

    The post discloses CVE-2026‑32277, a high‑severity DOM‑based XSS vulnerability in Connect‑CMS Cabinet Plugin list view for specific version ranges.

    0000031
    145 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32277: HIGH] Critical security update for Connect-CMS! Versions 1.35.0 to 1.41.0 and 2.35.0 to 2.41.0 affected by DOM-based XSS. Update to patched versions 1.41.1 and 2.41.1 now. #cybersecurity#cve,CVE-2026-32277,#cybersecurity https://cvefind.com/CVE-2026-32277

    Post summary

    The post reports a critical DOM‑based XSS in Connect‑CMS and directs users to upgrade to the patched versions 1.41.1 and 2.41.1.

    0000036
    606 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensource-workshopconnect-cms---

Explore more