CVE-2020-18264: Simple-Log Project Simple-Log

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".

Affected products

Published 2021-06-07. Last modified 2026-06-17.