Feed/CVE-2026-63684
CVE-2026-63684HIGHCVSS 8.8

CVE-2026-63684

Published Jul 22, 2026·Updated Jul 27, 2026

NVD Description

Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free