uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions.
Metrics
Affected Vendors & Products
References
History
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ubb Systems
Ubb Systems ubb.threads |
|
| Vendors & Products |
Ubb Systems
Ubb Systems ubb.threads |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions. | |
| Title | Cross-Site Request Forgery in UBB.threads | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2026-06-18T12:56:18.667Z
Updated: 2026-06-18T13:30:52.695Z
Reserved: 2026-06-12T11:03:23.916Z
Link: CVE-2026-54220
Updated: 2026-06-18T13:30:43.609Z
No data.
No data.