CVE-2026-54220
Deferred Deferred - Pending Action
Cross-Site Request Forgery in uBB.threads

Publication date: 2026-06-18

Last updated on: 2026-06-18

Assigner: CERT.PL

Description
uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-18
Last Modified
2026-06-18
Generated
2026-06-19
AI Q&A
2026-06-18
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
ubb threads to 7.7.5 (inc)
ubb threads From 7.7.5 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability in uBB.threads is a Cross-Site Request Forgery (CSRF) issue caused by the absence of protective mechanisms. This flaw allows an attacker to trick an authenticated user into performing actions they did not intend to execute.

Impact Analysis

This vulnerability can impact you by enabling attackers to perform unauthorized actions on your behalf without your consent, potentially leading to unwanted changes or operations within the uBB.threads application while you are authenticated.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54220. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart