CVE-2026-104059

CVE-2026-104059 published: Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation...

View full NVD advisory → ← Back to CVE watch