{"id":"CVE-2026-1468","title":"QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints","summary":"QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges.\nThis software does …","severity":"none","cwe":["CWE-352"],"published":"2026-03-06","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-1468","references":[{"url":"https://cert.pl/posts/2026/03/CVE-2026-1468","label":"cvd@cert.pl"},{"url":"https://opensolution.org/cms-system-quick-cms.html","label":"cvd@cert.pl"}],"tags":["nvd"],"epss":0.00222,"epssPercentile":0.13025,"ingestedAt":"2026-08-05T11:47:23.925Z","slug":"CVE-2026-1468","body":"## Overview\n\nQuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges.\nThis software does not implement any protection against this type of attack. All forms available in this software are potentially vulnerable.\n\nThis issue was fixed in a patch to version 6.8 published on 14.05.2026, deployments without this patch are still vulnerable\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}