---
id: CVE-2024-32643
title: Masa CMS is an open source Enterprise Content Management platform
summary: >-
  Masa CMS is an open source Enterprise Content Management platform. Prior to
  7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a
  /tag/ declaration, the CMS will render the page regardless of group
  restrictions. This …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: masacms
product: masacms
affected:
  - masacms < 7.2.8
  - 'masacms >= 7.3, < 7.3.13'
  - 'masacms >= 7.4.0, < 7.4.6'
patched:
  - masacms 7.4.6
published: '2025-12-03'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-32643'
references:
  - url: >-
      https://github.com/MasaCMS/MasaCMS/commit/d1a2e57ef8dbc50c87b178eacc85fcccb05f5b6c
    label: security-advisories@github.com
  - url: 'https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-f469-jh82-97fv'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00363
epssPercentile: 0.27573
ingestedAt: '2026-09-26T21:38:01.494Z'
---

## Overview

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

## Affected

- `masacms < 7.2.8`
- `masacms >= 7.3, < 7.3.13`
- `masacms >= 7.4.0, < 7.4.6`

## Remediation

Upgrade past the affected range:

- `masacms 7.4.6`
