MEDIUM
CVE-2026-9591
CVSS
6.9
Description
Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.
Weakness (CWE)
CWE-352
Cross-Site Request Forgery (CSRF)
EPSS Score
0.2%
Probability of exploitation in next 30 days
9.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.