CVE-2026-15080: Lingotek Ray Enterprise Translation
Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4.
Affected products
- Lingotek Ray Enterprise Translation: from 1.0, before 4.0.4 (fixed in 4.0.4); from 4.1.0, before 4.1.4 (fixed in 4.1.4); from 6.x-1.0, up to and including 6.x-1.40; from 7.x-1.0, up to and including 7.x-7.47; from 11.0.0, before 11.0.4 (fixed in 11.0.4)
Published 2026-07-10. Last modified 2026-08-07.