PT-2026-50426 · Unknown · Simplcommerce

·

CVE-2026-9591

·

Published

2026-06-17

·

Updated

2026-06-17

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SimplCommerce versions prior to commit 6233d73e
Description Cross-site request forgery (CSRF) occurs in the NewsItemApiController. This issue allows an unauthenticated remote attacker to create or modify news items with administrator privileges by submitting a crafted form to the '/api/news-items' endpoint. The flaw is caused by a lack of anti-CSRF protection, which is a mechanism used to prevent unauthorized commands from being transmitted from a user that the web application trusts.
Recommendations Update to the version containing commit 6233d73e or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9591

Affected Products

Simplcommerce