Cross-Site Request Forgery in SOPlanning by SOPlanning Team
CVE-2026-40549

5.1MEDIUM

Key Information:

Vendor

Soplanning

Vendor
CVE Published:
1 June 2026

What is CVE-2026-40549?

SOPlanning is susceptible to Cross-Site Request Forgery (CSRF) attacks through its groupe_save endpoints used for creating, modifying, and deleting records. This vulnerability allows malicious parties to exploit the trust that a web application has in an authenticated user. When a user visits a malicious website, the attacker can execute unauthorized commands on behalf of the user, potentially compromising sensitive data and application integrity. This issue is present in SOPlanning versions 1.55 and earlier, necessitating immediate action to secure applications against potential exploitation.

Affected Version(s)

SOPlanning 0 <= 1.55

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Jaworski
.