studiocms records
8 published records for vendor studiocms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-639 Authorization Bypass Through User-Controlled Key6
- CWE-269 Improper Privilege Management1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2026-30944Proof of concept | StudioCMS Affected by Privilege Escalation via Insecure API Token Generationstudiocms · studiocms · CWE-639 | High8.8 | — | 0.5% | Mar 10, 2026 |
28Monitor | CVE-2026-30945Proof of concept | StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Servicestudiocms · studiocms · CWE-639 | High7.1 | — | 0.4% | Mar 10, 2026 |
28Monitor | CVE-2026-32103No exploit | StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generationstudiocms · studiocms · CWE-639 | High7.2 | — | 0.4% | Mar 11, 2026 |
28Monitor | CVE-2026-32106No exploit | StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accountsstudiocms · studiocms · CWE-269 | High7.2 | — | 0.4% | Mar 11, 2026 |
26Monitor | CVE-2026-24134Proof of concept | StudioCMS has an Authorization Bypass Through User-Controlled Keystudiocms · studiocms · CWE-639 | Medium6.5 | — | 0.3% | Jan 27, 2026 |
25Monitor | CVE-2026-32101No exploit | StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth Checkstudiocms · studiocms · CWE-863 | Medium6.3 | — | 0.3% | Mar 11, 2026 |
21Monitor | CVE-2026-32104No exploit | StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settingsstudiocms · studiocms · CWE-639 | Medium5.4 | — | 0.3% | Mar 11, 2026 |
10Monitor | CVE-2026-32638No exploit | StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokensstudiocms · studiocms · CWE-639 | Low2.7 | — | 0.4% | Mar 18, 2026 |
- CVE-2026-3094435Monitor
StudioCMS Affected by Privilege Escalation via Insecure API Token Generation
HighCVSS 8.8Proof of conceptEPSS 1%studiocms · studiocmsMar 10, 2026
- CVE-2026-3094528Monitor
StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service
HighCVSS 7.1Proof of conceptEPSS 0%studiocms · studiocmsMar 10, 2026
- CVE-2026-3210328Monitor
StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation
HighCVSS 7.2No exploitEPSS 0%studiocms · studiocmsMar 11, 2026
- CVE-2026-3210628Monitor
StudioCMS: REST API Missing Rank Check Allows Admin to Create Peer Admin Accounts
HighCVSS 7.2No exploitEPSS 0%studiocms · studiocmsMar 11, 2026
- CVE-2026-2413426Monitor
StudioCMS has an Authorization Bypass Through User-Controlled Key
MediumCVSS 6.5Proof of conceptEPSS 0%studiocms · studiocmsJan 27, 2026
- CVE-2026-3210125Monitor
StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth Check
MediumCVSS 6.3No exploitEPSS 0%studiocms · studiocmsMar 11, 2026
- CVE-2026-3210421Monitor
StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settings
MediumCVSS 5.4No exploitEPSS 0%studiocms · studiocmsMar 11, 2026
- CVE-2026-3263810Monitor
StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens
LowCVSS 2.7No exploitEPSS 0%studiocms · studiocmsMar 18, 2026