Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hwj7-4vgc-j3v9 | Amazon S3 for Craft CMS has an Information Disclosure vulnerability |
Wed, 18 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms aws-s3 |
|
| Vendors & Products |
Craftcms
Craftcms aws-s3 |
Wed, 18 Mar 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a list of buckets the plugin has access to. The `BucketsController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.5 of the plugin to mitigate the issue. | |
| Title | Amazon S3 for Craft CMS has an Information Disclosure vulnerability | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-18T13:30:56.737Z
Reserved: 2026-03-11T15:05:48.397Z
Link: CVE-2026-32265
Updated: 2026-03-18T13:30:51.217Z
Status : Deferred
Published: 2026-03-18T04:17:27.337
Modified: 2026-04-16T14:46:24.290
Link: CVE-2026-32265
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:59:23Z
Github GHSA