Opensource Workshop maintains a narrowly scoped vulnerability footprint centered on its Connect CMS product, a content-management system with a modest but persistent disclosure history. The vendor's profile reflects application-layer exposure typical of web-based CMS platforms, where remediation depends on timely patching by site operators and administrators. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensource Workshop over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32277HIGH Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin l | Mar 23, 2026 | 8.7 | 30 | NO | NO |
CVE-2026-32276HIGH Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated use | Mar 23, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-32300HIGH Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authoriz | Mar 23, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-32299HIGH Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authoriz | Mar 23, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-32279MEDIUM Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Reques | Mar 23, 2026 | 6.8 | 22 | NO | NO |
CVE-2026-32278MEDIUM Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site | Mar 23, 2026 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensource Workshop.
Media articles that mention a CVE ID that affects a product developed by Opensource Workshop — matched by CVE ID, not by vendor name.