CVE-2026-40549EPSS p8.0%
CVE-2026-40549CVE-2026-40549
Description
SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged GET or POST request to the application.
This issue affects SOPlanning version 1.55 and below.
Scoring
| EPSS | 0.18% probability of exploitation · percentile 8.0% · 2026-08-03T12:00:16Z |
| Last modified | 2026-07-22 |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.