Security: opensource-workshop/connect-cms
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Arbitrary Code Execution by an Authenticated User in the Code Study PluginGHSA-hxqw-6qv7-cqfv published
Mar 23, 2026 by gakigakiHigh -
Server-Side Request Forgery (SSRF) in the External Page Migration Feature of the Page Management PluginGHSA-jh46-85jr-6ph9 published
Mar 23, 2026 by gakigakiModerate -
Stored Cross-Site Scripting (XSS) in the File Field of the Form PluginGHSA-mv3p-7p89-wq9p published
Mar 23, 2026 by gakigakiHigh -
DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List ViewGHSA-cmfh-mpmf-fmq4 published
Mar 23, 2026 by gakigakiHigh -
Information Disclosure Due to Improper Authorization in the Page Content Retrieval FeatureGHSA-62ch-j6x7-722j published
Mar 23, 2026 by gakigakiHigh -
Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User InformationGHSA-qr6x-wvxr-8hm9 published
Mar 23, 2026 by gakigakiHigh -
Access control vulnerabilityGHSA-5rjc-jc28-cwgg published
Feb 7, 2025 by akagane99Moderate -
[サイト内検索] 閲覧を限定している情報が見えてしまうGHSA-2237-5r9w-vm8j published
Feb 7, 2025 by akagane99Critical -
Privileges Escalation VulnerabilityGHSA-qxh3-jgvh-x55j published
Jul 3, 2023 by akagane99Moderate
Learn more about advisories related to opensource-workshop/connect-cms in the GitHub Advisory Database