SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65539

HIGH · CVSS 7.1 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to exploit Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap versions up to 4.0, potentially leading to unauthorized actions being performed on behalf of users without their consent. This poses a significant risk to web applications utilizing this plugin, as it can compromise user data and site integrity. Organizations using affected versions should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-65539
Severity
HIGH
CVSS
7.1
EPSS
0.09%

Original NVD Description

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.