Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/studiocms — 7 CVEs · VulnScope
pkg:npm/
studiocms
7 total CVEs
HIGH
2
MEDIUM
4
LOW
1
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.8
CVE-2026-30944
StudioCMS has Privilege Escalation via Insecure API Token Generation
from 0, < 0.4.0
HIGH
7.1
CVE-2026-30945
StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service
from 0, < 0.4.0
MEDIUM
6.8
CVE-2026-32103
StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation
from 0, < 0.4.3
MEDIUM
6.5
StudioCMS has Authorization Bypass Through User-Controlled Key
from 0, < 0.2.0
MEDIUM
5.4
StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settings
from 0, < 0.4.3
MEDIUM
4.7
StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts
from 0, < 0.4.3
LOW
2.7
StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
from 0, < 0.4.4
CVE-2026-24134
CVE-2026-32104
CVE-2026-32106
CVE-2026-32638