CVE-2026-32277 identifies a DOM-based Cross-Site Scripting (XSS) vulnerability in Connect-CMS versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, specifically located in the Cabinet Plugin list view. This flaw is rated 8.7 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N), indicating it can be exploited over a network with low attack complexity and low privileges, requiring user interaction, to achieve high confidentiality and integrity impacts. There is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB, and it is not in the CISA KEV catalog. Community attention is minimal, with only two mentions recorded. Affected systems should be updated to Connect-CMS versions 1.41.1 or 2.41.1 to apply the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.35.0, < 1.41.1CPE matchmatch criteria | cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:* | ||
>= 2.35.0, < 2.41.1CPE matchmatch criteria | cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.