CVE-2016-3691: Kallithea-Scm Kallithea

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.

Affected products

Published 2017-04-24. Last modified 2026-06-17.