Please report security vulnerabilities to contact@synaptikcms.com.
Include as much detail as possible: affected version, steps to reproduce, and potential impact. We will acknowledge receipt within 48 hours and aim to release a patch as soon as possible.
Other bugs and issues can be reported at https://github.com/synaptikcms/synaptik-cms/issues.
We are grateful to the following researchers who responsibly disclosed vulnerabilities and helped improve SynaptikCMS.
| Researcher | Version | Finding |
|---|---|---|
| @treeandcoffee | 1.3.4.4 | Full security audit — 1 critical, 7 high, 9 medium findings across admin endpoints, data layer, session handling, and file management |
| Dinesh Goud | 1.3.4.4 | File manager: path traversal via rename/move, missing extension validation |