CVE-2026-3327: Datocms Web Previews
Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Authenticated Iframe Injection in Dato CMS Web Previews plugin. This vulnerability permits a malicious authenticated user to circumvent the restriction enforced on the configured frontend URL, enabling the loading of arbitrary external resources or origins. This issue affects Web Previews < v1.0.31.
Affected products
- Datocms Web Previews: before 1.0.31 (fixed in 1.0.31)
Published 2026-02-27. Last modified 2026-06-17.