Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 20 Jun 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:simplcommerce:simplcommerce:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simplcommerce
Simplcommerce simplcommerce |
|
| Vendors & Products |
Simplcommerce
Simplcommerce simplcommerce |
Wed, 17 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection. | |
| Title | Cross-Site Request Forgery (CSRF) in SimplCommerce News Module | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmarx
Published:
Updated: 2026-06-18T13:46:21.749Z
Reserved: 2026-05-26T13:36:23.358Z
Link: CVE-2026-9591
Updated: 2026-06-17T15:02:03.251Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T20:45:03Z