CVE-2026-32278 | opensource-workshop connect-cms up to 1.41.0/2.41.0 Form Plugin File unrestricted upload (GHSA-mv3p-7p89-wq9p)
A vulnerability has been found in opensource-workshop connect-cms up to 1.41.0/2.41.0 and classified as critical. This affects an unknown function of the component Form Plugin. Performing a manipulation of the argument File results in unrestricted upload.
This vulnerability is known as CVE-2026-32278. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.