
CVE-2026-28508 Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoi… https://www.cve.org/CVERecord?id=CVE-2026-28508
Post summary
The post provides a brief disclosure that a logic error in Idno's API authentication flow allows a CSRF attack on the URL unfurl service prior to version 1.6.4.
