CVE-2026-66652

Summary

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery.

This issue affects Grand Tour: from n/a through 5.5.1.

Affected Software

VendorProductVersion RangeStatus
ThemeGoodsGrand Tourn/a <= 5.5.1affected

Weaknesses

  • CWE-352: CWE-352 Cross-Site Request Forgery (CSRF)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References