CVE-2026-9591: Simplcommerce
Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF protection.
Affected products
- Simplcommerce Simplcommerce
Published 2026-06-17. Last modified 2026-06-18.