CVE-2026-9591: Simplcommerce

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.

Affected products

Published 2026-06-17. Last modified 2026-06-18.