AlchemyCMS has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 6.4 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- alchemy_cms 2
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-57579High· 7.5Alchemy is an open source content management system engine written in Ruby on Rails53CVE-2026-86777Medium· 5.3AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes41
AlchemyCMS vulnerabilities
CVEs affecting AlchemyCMS, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-57579High· 7.5PoCAlchemy is an open source content management system engine written in Ruby on Rails
Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the unauthenticated GET /api/pages/nested endpoint implemented by Api::PagesController#nested in app/control…
▾ MidnightAlchemyCMS · alchemy_cmsEPSS 0.47%via NVD
CVE-2026-86777Medium· 5.3PoCAlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes
AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication…
▾ TwilightAlchemyCMS · alchemy_cmsEPSS 0.41%via NVD