THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-1468 — QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does not implement any protection against this t

[NVD] CVE-2026-1468 — QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does not implement any protection against this t

lownvdPublished 2026-03-06

CVE-2026-1468 CVSS: None Published: 2026-03-06T11:16:08.613

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does not implement any protection against this type of attack. All forms available in this software are po

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-1468