# QuickCMS version 6.8 contains a Cross-Site Request Forgery vulnerability (CVE-2026-1468)…

Published: 2026-03-06 · Severity: medium
Canonical: https://vorant.io/reports/d5e173f7-79ef-4d46-923f-7066952e8830/quickcms-version-6-8-contains-a-cross-site-request-forgery-vulnerability-cve

> QuickCMS version 6.8 contains a Cross-Site Request Forgery vulnerability (CVE-2026-1468) affecting multiple endpoints with no CSRF protection implemented.

CERT Polska coordinated disclosure of CVE-2026-1468, a Cross-Site Request Forgery (CSRF) vulnerability affecting QuickCMS software. The vulnerability allows attackers to craft malicious websites that, when visited by authenticated victims, automatically send POST requests with the victim's privileges. The software lacks any CSRF protection mechanisms, making all forms within the application potentially exploitable.

Version 6.8 has been confirmed vulnerable through testing, though other versions remain untested and may also be affected. The vendor was notified early in the disclosure process but did not provide information about the vulnerability details or the full range of affected versions.

The vulnerability was responsibly reported by Michał Biesiada and coordinated through CERT Polska's vulnerability disclosure process. Organizations using QuickCMS should assess their exposure and monitor for vendor patches or mitigation guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1468

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1468

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d5e173f7-79ef-4d46-923f-7066952e8830/quickcms-version-6-8-contains-a-cross-site-request-forgery-vulnerability-cve.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
