📦 Studiocms

by Studiocms

🔍 What is Studiocms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-32101

HIGH CVSS 7.6 Mar 11, 2026

This vulnerability allows any authenticated user, even with the lowest 'visitor' role, to bypass authorization checks and perform unauthorized file operations on S3 storage. Affected systems are Studi...

CVE-2026-30944

HIGH CVSS 8.8 Mar 10, 2026

This vulnerability allows any authenticated user with at least Editor permissions in StudioCMS to generate API tokens for any other user, including administrative accounts. This results in full privil...

CVE-2026-32103

MEDIUM CVSS 6.8 Mar 11, 2026

This vulnerability allows any authenticated admin user in StudioCMS to generate password reset tokens for any other user, including the highest-privileged owner account. This enables complete account ...

CVE-2026-32106

MEDIUM CVSS 4.7 Mar 11, 2026

StudioCMS versions before 0.4.3 have inconsistent authorization checks between REST API and Dashboard API user creation endpoints. This allows authenticated admin users to create additional admin acco...

CVE-2026-24134

MEDIUM CVSS 6.5 Jan 28, 2026

StudioCMS versions before 0.2.0 contain a Broken Object Level Authorization vulnerability that allows users with the 'Visitor' role to access draft content created by Editor, Admin, or Owner users. Th...