216.73.217.22

CVE-2026-9591

· Published 17/06/2026 16:18 · Author: The MITRE Corporation

Labels: CVE-2026-9591 2026-06-17596c5446-0ce5-4ba2-aa66-48b3b757a647CVE-2026-9591CWE-352

Essential information

Published
17/06/2026 16:18
Modified
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CWE-352
CVSS vector

CVSS metrics

Description

Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.

NVD status

NVD
View on NVD