CVE-2026-53760Medium· 5.2▾ TwilightPoC availableAdmidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 28.6 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
Exploit / PoC code exists
Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because these are top-level navigations, browsers include SameSite=Lax session cookies. An attacker crafts a malicious page that, when an authenticated administrator visits it, triggers arbitrary plugin operations. The uninstall operation executes DROP TABLE SQL scripts and destroys plugin data. This issue has been patched via commit 056b1bd.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
admidio/admidio <= 5.0.11Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47227Medium· 6.5Admidio is an open-source user management solution
CVE-2026-47230Medium· 6.5Admidio is an open-source user management solution
CVE-2019-13529High· 8.8An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior
CVE-2026-63373Medium· 4.2draw.io is a configurable diagramming and whiteboarding application
CVE-2026-54510High· 7.1Speakr is a personal, self-hosted web application designed for transcribing audio recordings
CVE-2026-59148High· 8.8Mockoon provides way to design and run mock APIs