---
id: CVE-2022-26173
title: >-
  JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF)
  via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers
  to arbitrarily add admin accounts.
summary: >-
  JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF)
  via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers
  to arbitrarily add admin accounts.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-352
vendor: jforum
product: jforum
affected:
  - jforum = 2.8.0
published: '2022-06-16'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-26173'
references:
  - url: 'https://community.jforum.net/posts/list/248.page'
    label: cve@mitre.org
  - url: 'https://github.com/WULINPIN/CVE/blob/main/JForum/poc.html'
    label: cve@mitre.org
  - url: 'https://jforum.net/'
    label: cve@mitre.org
  - url: 'https://sourceforge.net/p/jforum2/wiki2/NewFeatures281/'
    label: cve@mitre.org
  - url: 'http://jforum.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://community.jforum.net/posts/list/248.page'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/WULINPIN/CVE/blob/main/JForum/poc.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://jforum.net/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://sourceforge.net/p/jforum2/wiki2/NewFeatures281/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00712
epssPercentile: 0.51545
ingestedAt: '2026-07-06T17:03:24.428Z'
---

## Overview

JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

## Affected

- `jforum = 2.8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
