{"id":"CVE-2025-58468","title":"A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center","summary":"A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities.\n\nWe have already fixed the vulnerabi…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-352"],"vendor":"qnap","product":"notification_center","affected":["notification_center >= 1.10.0, < 1.10.0.3291"],"patched":["notification_center 1.10.0.3291"],"published":"2026-06-10","updated":"2026-08-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-58468","references":[{"url":"https://www.qnap.com/en/security-advisory/qsa-26-13","label":"security@qnapsecurity.com.tw"}],"tags":["nvd"],"epss":0.00156,"epssPercentile":0.05127,"ingestedAt":"2026-08-06T13:59:38.543Z","slug":"CVE-2025-58468","body":"## Overview\n\nA cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities.\n\nWe have already fixed the vulnerability in the following version:\nNotification Center 1.10.0.3291 and later\n\n## Affected\n\n- `notification_center >= 1.10.0, < 1.10.0.3291`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `notification_center 1.10.0.3291`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}