Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ubb Systems
Ubb Systems ubb.threads |
|
| Vendors & Products |
Ubb Systems
Ubb Systems ubb.threads |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions. | |
| Title | Cross-Site Request Forgery in UBB.threads | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-06-18T13:30:52.695Z
Reserved: 2026-06-12T11:03:23.916Z
Link: CVE-2026-54220
Updated: 2026-06-18T13:30:43.609Z
Status : Deferred
Published: 2026-06-18T14:17:30.530
Modified: 2026-06-18T18:05:54.947
Link: CVE-2026-54220
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:56:14Z