CVE-2026-104070

CVE-2026-104070 published: The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authoriza...

View full NVD advisory → ← Back to CVE watch