← Back to search

CVE-2026-78295

8.8 HIGH

Published 2026-09-17 · Updated 2026-09-17

AI risk analysis

Summary
The flaw is an unauthenticated Cross Site Request Forgery (CSRF) vulnerability in Xagio SEO versions 7.1.0.43 and earlier, allowing attackers to perform unauthorized actions on behalf of authenticated users without their consent.
Exploitability
Exploitation is relatively straightforward as it requires the attacker to trick an authenticated user into performing actions on the affected Xagio SEO instance without their knowledge.
Blast radius
If exploited, this vulnerability could result in unauthorized changes to the website's content or configuration, potentially leading to data loss or compromise of user information.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Xagio SEO version 7.1.0.44 or later.
csrfwebauth-bypass

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-352

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.