Report a vulnerability through GitHub's private vulnerability reporting: open the form on github.com/cboxdk/cms, or choose Security, then Report a vulnerability, on the repository. Only the maintainers see the report.
Do not open a public issue, pull request or discussion about a vulnerability.
A useful report says what is affected, how to reproduce it, and what an attacker gains. A failing test or a small script helps most.
Cbox CMS is pre-release and has no tagged version. A fix lands on the main branch.
Security in the documentation describes the rules the code holds today, and Scope says plainly what it does not protect yet. A report about something the scope lists as not protected yet is still welcome.