alchemy_cms vulnerabilities
CVEs whose affected-version data names the alchemy_cms package (rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-57579High· 7.5PoCAlchemy is an open source content management system engine written in Ruby on Rails
Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the unauthenticated GET /api/pages/nested endpoint implemented by Api::PagesController#nested in app/control…
CVE-2026-86777Medium· 5.3PoCAlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes
AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication…
GHSA-mqq5-j7w8-2hghHigh· 7.5AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content