CVE-2019-5630: RAPID7 Nexpose

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.

Affected products

  • RAPID7 Nexpose: from 6.5.0, up to and including 6.5.68

Published 2019-07-03. Last modified 2026-06-17.