CVE-2026-32276 | opensource-workshop connect-cms up to 1.41.0/2.41.0 code injection (GHSA-hxqw-6qv7-cqfv)
A vulnerability, which was classified as critical, has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0. The affected element is an unknown function. This manipulation causes code injection.
This vulnerability appears as CVE-2026-32276. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.