CVE-2025-29722
Published
CVSS v3
6.3
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS
Description
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.