๐Ÿ” CVE Alert

CVE-2026-40309

UNKNOWN 0.0

Masa CMS CSRF in trash management allows unauthorized permanent deletion of deleted content

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function does not validate anti-CSRF tokens for trash management requests. An attacker can induce a logged-in administrator to submit a forged request that empties the trash and permanently deletes all deleted content. This can cause irreversible data loss and disrupt recovery of content intended for restoration. This issue has been fixed in versions 7.2.10, 7.3.15, 7.4.10, and 7.5.3. As a workaround, restrict access to the administrative backend, use browser isolation for administrative sessions, and maintain current database backups to recover from unauthorized deletion.

CWE CWE-352
Vendor masacms
Product masacms
Published May 6, 2026
Stay Ahead of the Next One

Get instant alerts for masacms masacms

Be the first to know when new unknown vulnerabilities affecting masacms masacms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MasaCMS / MasaCMS
< 7.2.10 >= 7.3.0, < 7.3.15 >= 7.4.0, < 7.4.10 >= 7.5.0, < 7.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-9f35-q62j-vm5j