Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Studiocms HIGH 7.2
CVE-2026-32103

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studiocms_api/dashboard/create-reset…

Fix: 0.4.3+
Fix from $1,950 2026-03-11
Studiocms HIGH 7.2
CVE-2026-32106

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API createUser endpoint uses string-b…

Fix: 0.4.3+
Fix from $1,950 2026-03-11
Studiocms MEDIUM 6.3
CVE-2026-32101

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage manager's isAuthorized() functi…

Fix: 0.3.1+
Fix from $1,600 2026-03-11
Studiocms MEDIUM 5.4
CVE-2026-32104

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the updateUserNotifications endpoint accepts a…

Fix: 0.4.3+
Fix from $1,600 2026-03-11
Studiocms HIGH 8.8
CVE-2026-30944

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoi…

Fix: 0.4.0+
Fix from $1,950 2026-03-10
Studiocms HIGH 7.1
CVE-2026-30945

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens…

Fix: 0.4.0+
Fix from $1,950 2026-03-10
Studiocms MEDIUM 6.5
CVE-2026-24134

StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authoriz…

Fix: 0.2.0+
Fix from $1,600 2026-01-28