CVE-2025-26903
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 352
Summary
CVE-2025-26903 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the RealMag777 InPost Gallery. This issue enables malicious actors to trick users into executing unintended actions on their behalf, such as modifying or deleting sensitive data. The impacted versions of InPost Gallery range from n/a to 2.1.4.3, and users are encouraged to update to a patched version to mitigate this risk. This flaw can lead to serious consequences, including data loss or unauthorized access, and should be addressed promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.