CVE-2023-27889: Lqd Liquid Speech Balloon

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in LIQUID SPEECH BALLOON versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of a user and to perform unintended operations by having a user view a malicious page.

Affected products

  • Lqd Liquid Speech Balloon: before 1.2 (fixed in 1.2)

Published 2023-05-10. Last modified 2026-06-17.