CVE-2026-1213: Askbot

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.

Affected products

  • Askbot Askbot: up to and including 0.12.2

Published 2026-01-27. Last modified 2026-06-17.