VORANT. Threat Intelligence Sign in Get the full feed

QuickCMS CSRF flaw disclosed unpatched

medium vulnerability

QuickCMS 6.8 lacks CSRF protections on all forms, letting attackers forge authenticated POST requests via a malicious webpage.

CERT Polska disclosed CVE-2026-1468, a Cross-Site Request Forgery vulnerability affecting QuickCMS software. The flaw allows an attacker to craft a malicious website that, when visited by an authenticated victim, silently submits POST requests using the victim's session privileges. Because QuickCMS implements no CSRF protections across any of its forms, all form-based endpoints are potentially exploitable.

Only version 6.8 was confirmed vulnerable during testing; other versions were not evaluated but may share the same weakness. The vendor was notified during the disclosure process but did not respond with vulnerability details or a confirmed affected version range, meaning no official patch or mitigation guidance is currently available. CERT Polska coordinated the disclosure following a report from researcher Michał Biesiada.

Mentioned in this report

Vulnerabilities CVE-2026-1468

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1468

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free