CVE-2026-32279

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Server-Side Request Forgery (SSRF) issue exists in the external page migration feature of the Page Management Plugin. Versions 1.41.1 and 2.41.1 contain a patch.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:*
cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:*

History

24 Mar 2026, 20:28

Type Values Removed Values Added
References () https://github.com/opensource-workshop/connect-cms/commit/4a1a64a8f768a53e06a4239e25782d9e2e88fc63 - () https://github.com/opensource-workshop/connect-cms/commit/4a1a64a8f768a53e06a4239e25782d9e2e88fc63 - Patch
References () https://github.com/opensource-workshop/connect-cms/commit/617a874e14b8476da7c0760a06384b9da21bdd4f - () https://github.com/opensource-workshop/connect-cms/commit/617a874e14b8476da7c0760a06384b9da21bdd4f - Patch
References () https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1 - () https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1 - Release Notes
References () https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1 - () https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1 - Release Notes
References () https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-jh46-85jr-6ph9 - () https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-jh46-85jr-6ph9 - Vendor Advisory
CPE cpe:2.3:a:opensource-workshop:connect-cms:*:*:*:*:*:*:*:*
First Time Opensource-workshop connect-cms
Opensource-workshop
Summary
  • (es) Connect-CMS es un sistema de gestión de contenidos. En las versiones de la serie 1.x hasta la 1.41.0 inclusive y las versiones de la serie 2.x hasta la 2.41.0 inclusive, existe un problema de falsificación de petición del lado del servidor (SSRF) en la función de migración de páginas externas del plugin de Gestión de Páginas. Las versiones 1.41.1 y 2.41.1 contienen un parche.

23 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 22:16

Updated : 2026-03-24 20:28


NVD link : CVE-2026-32279

Mitre link : CVE-2026-32279

CVE.ORG link : CVE-2026-32279


JSON object : View

Products Affected

opensource-workshop

  • connect-cms
CWE
CWE-918

Server-Side Request Forgery (SSRF)