CVE-2026-39170

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.

Published 2026-06-09. Last modified 2026-07-23.