CVE-2023-37650: Agentejo Cockpit

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.

Affected products

  • Agentejo Cockpit: up to and including 2.5.2

Published 2023-07-20. Last modified 2026-06-17.