CVE-2025-60535

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request.

Published 2025-10-14. Last modified 2026-07-05.