CVE-2026-13243: Victorkane Salesforce Suite

Medium severity, CVSS 4.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3.

Affected products

  • Victorkane Salesforce Suite: before 5.1.3 (fixed in 5.1.3)

Published 2026-07-10. Last modified 2026-08-06.