The open-source Content Management System (CMS) platform disclosed that an internal resource directory containing unencrypted developer profiles, corporate email accounts, and salted password hashes was left exposed on a public-facing AWS bucket.