Skip to main content
Loading…
    CVE-2026-32638 — StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `getUsers` endpoint in StudioCMS uses the attacker-controlled `rank` query parameter — CVE Database · The Intelligence Room