pkg:npm/studiocms
7 total CVEsHIGH2MEDIUM4LOW1
✅ Check your installed version
All known vulnerabilities
- from 0, < 0.4.0
- from 0, < 0.4.0
- MEDIUM6.8CVE-2026-32103StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generationfrom 0, < 0.4.3
- from 0, < 0.2.0
- MEDIUM5.4CVE-2026-32104StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settingsfrom 0, < 0.4.3
- MEDIUM4.7CVE-2026-32106StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accountsfrom 0, < 0.4.3
- from 0, < 0.4.4