CVE-2026-78295
8.8 HIGHPublished 2026-09-17 · Updated 2026-09-17
AI risk analysis
- Summary
- The flaw is an unauthenticated Cross Site Request Forgery (CSRF) vulnerability in Xagio SEO versions 7.1.0.43 and earlier, allowing attackers to perform unauthorized actions on behalf of authenticated users without their consent.
- Exploitability
- Exploitation is relatively straightforward as it requires the attacker to trick an authenticated user into performing actions on the affected Xagio SEO instance without their knowledge.
- Blast radius
- If exploited, this vulnerability could result in unauthorized changes to the website's content or configuration, potentially leading to data loss or compromise of user information.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Xagio SEO version 7.1.0.44 or later.
csrfwebauth-bypass
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-352
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2025-15399
- HIGHCVE-2026-62062
- CRITICALCVE-2026-71238PoC
- HIGHCVE-2026-61687PoC
- MEDIUMCVE-2026-63373PoC
- CRITICALCVE-2026-70376PoC
- HIGHCVE-2026-84084
- HIGHCVE-2026-88418PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.