QuickCMS CSRF flaw affects all forms
QuickCMS 6.8 is vulnerable to Cross-Site Request Forgery across all endpoints, allowing attackers to execute actions with victim privileges via crafted websites.
CERT Polska has disclosed a Cross-Site Request Forgery (CSRF) vulnerability in QuickCMS software, tracked as CVE-2026-1468. The vulnerability affects all forms and endpoints in the application, which lacks any CSRF protection mechanisms. An attacker can craft a malicious website that, when visited by an authenticated QuickCMS user, automatically sends POST requests using the victim's session privileges.
Version 6.8 has been confirmed as vulnerable through testing, though other versions remain untested and may also be affected. The vendor was notified early in the disclosure process but did not provide details about the vulnerability scope or confirm the full range of affected versions. The vulnerability was discovered and responsibly reported by Michał Biesiada.
Organizations using QuickCMS should assess their exposure and monitor for vendor patches. The lack of vendor response suggests remediation guidance may be limited, and affected deployments may need to implement compensating controls such as additional CSRF tokens or authentication layers until an official fix is available.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1468
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free