CVE-2025-26903

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 352

Summary

CVE-2025-26903 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the RealMag777 InPost Gallery. This issue enables malicious actors to trick users into executing unintended actions on their behalf, such as modifying or deleting sensitive data. The impacted versions of InPost Gallery range from n/a to 2.1.4.3, and users are encouraged to update to a patched version to mitigate this risk. This flaw can lead to serious consequences, including data loss or unauthorized access, and should be addressed promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share