CVE-2026-40549
Cross-Site Request Forgery in SOPlanning
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
5th
SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged GET or POST request to the application. This issue affects SOPlanning version 1.55 and below.
| CWE | CWE-352 |
| Vendor | soplanning |
| Product | soplanning |
| Published | Jun 1, 2026 |
| Last Updated | Jun 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for soplanning soplanning
Be the first to know when new unknown vulnerabilities affecting soplanning soplanning are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
SOPlanning / SOPlanning
0 ≤ 1.55
References
Credits
Łukasz Jaworski