Vulnerability Description
Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Squidex/squidex
- https://lgnas.gitbook.io/findings/cve-2026-31016
- https://lgnas.gitbook.io/hello/silly-findings/squidex-cms-csrf
- https://www.youtube.com/watch?v=62ay_jrwUcI
- https://lgnas.gitbook.io/findings/cve-2026-31016
FAQ
What is CVE-2026-31016?
CVE-2026-31016 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint
How severe is CVE-2026-31016?
CVE-2026-31016 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-31016?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.