CVE-2025-31439: Tobias .merz Browser Caching With .htaccess
Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Cross-Site Request Forgery (CSRF) vulnerability in tobias_.MerZ Browser Caching with .htaccess allows Cross Site Request Forgery. This issue affects Browser Caching with .htaccess: from 1.2.1 through n/a.
Affected products
- Tobias .merz Browser Caching With .htaccess: version 1.2.1 only
Published 2025-03-28. Last modified 2026-06-17.