PatchSiren

CSZ CMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH CSZ CMS CVE published 2026-08-11

CVE-2026-72601

A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions, including personally identifiable information, via the admin form-submission viewer. The viewer endpoint lacks an authentication check, and the framework authentication helper fails open. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Organizations us [truncated]