CVE-2020-16610: Hoosk

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Hoosk Codeigniter CMS before 1.7.2 is affected by a Cross Site Request Forgery (CSRF). When an attacker induces authenticated admin user to a malicious web page, any accounts can be deleted without admin user's intention.

Affected products

  • Hoosk Hoosk: before 1.7.2 (fixed in 1.7.2)

Published 2020-08-28. Last modified 2026-06-17.