# QuickCMS CSRF flaw disclosed unpatched

Published: 2026-03-06 · Severity: medium
Canonical: https://vorant.io/reports/808f6d42-7dfd-5c47-8e2e-6de2aee70efc/quickcms-csrf-flaw-disclosed-unpatched

> QuickCMS 6.8 lacks CSRF protections on all forms, letting attackers forge authenticated POST requests via a malicious webpage.

CERT Polska disclosed CVE-2026-1468, a Cross-Site Request Forgery vulnerability affecting QuickCMS software. The flaw allows an attacker to craft a malicious website that, when visited by an authenticated victim, silently submits POST requests using the victim's session privileges. Because QuickCMS implements no CSRF protections across any of its forms, all form-based endpoints are potentially exploitable.

Only version 6.8 was confirmed vulnerable during testing; other versions were not evaluated but may share the same weakness. The vendor was notified during the disclosure process but did not respond with vulnerability details or a confirmed affected version range, meaning no official patch or mitigation guidance is currently available. CERT Polska coordinated the disclosure following a report from researcher Michał Biesiada.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1468

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1468

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/808f6d42-7dfd-5c47-8e2e-6de2aee70efc/quickcms-csrf-flaw-disclosed-unpatched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
