CVE-2015-9292: 6kbbs

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).

Affected products

  • 6kbbs 6kbbs: version 7.1 only; version 8.0 only

Published 2019-08-08. Last modified 2026-06-17.