CVE-2026-38934
the affected product
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php
- CVSS
- 8.8
- EPSS
- 0.22% 13.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.28