Cross-Site Request Forgery in PbootCMS User Management by PbootCMS
CVE-2026-92383

5.3MEDIUM

Key Information:

Vendor

PbootCMS

Status
Vendor
CVE Published:
16 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-92383?

A security vulnerability has been identified in PbootCMS affecting versions up to 3.2.24, specifically within the UserController module. The vulnerability originates from inadequate validation within functions responsible for user deletion and modification, exposing the application to cross-site request forgery exploits. This flaw allows attackers to potentially execute unauthorized requests from remote locations, compromising user data integrity and security. To mitigate this risk, users are recommended to upgrade to PbootCMS version 3.2.25, which addresses this issue through a critical patch. The patch identifier is c25241a0964742cefb7f698efbb6c38b868d6ff7.

Affected Version(s)

PbootCMS 3.2.0

PbootCMS 3.2.1

PbootCMS 3.2.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

rockmelodeis (VulDB User)
.