NVD HIGH: CVE-2026-66416 — Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows u...
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, P
CVE-2026-66416