THREAT OPS › Threat News › [NVD] CVE-2026-29113 (MEDIUM 4.3) — Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce
[NVD] CVE-2026-29113 (MEDIUM 4.3) — Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce
CVE-2026-29113 CVSS: 4.3 MEDIUM Published: 2026-03-10T20:16:38.060
Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce a CSRF token, an attacker can force a logged-in vict
Indicators of compromise
- CVE-2026-29113cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-29113