CVE-2026-5624: ProjectSend upload.php cross-site request forgery

Published Apr 6, 2026
·
Updated

A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version r2029 is able to resolve this issue. The patch is named 2c0d25824ab571b6c219ac1a188ad9350149661b. You should upgrade the affected component.

Affected Software

1 affected component
ProjectSend ProjectSend=r2002

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ProjectSend to a version that resolves this vulnerability.

    Fixed in r2029Patch 2c0d25824ab571b6c219ac1a188ad9350149661b

Event History

Apr 6, 2026
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Nov 16, 58530
Event
via NVD·03:50 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-5624?

CVE-2026-5624 is rated as a medium severity cross-site request forgery vulnerability.

2

How do I fix CVE-2026-5624?

To fix CVE-2026-5624, upgrade ProjectSend to the latest version beyond r2002 that addresses this vulnerability.

3

What is affected by CVE-2026-5624?

CVE-2026-5624 specifically affects ProjectSend version r2002 due to an issue in the upload.php file.

4

Can CVE-2026-5624 be exploited remotely?

Yes, CVE-2026-5624 can be exploited remotely, allowing attackers to perform unauthorized actions.

5

What type of vulnerability is CVE-2026-5624?

CVE-2026-5624 is a cross-site request forgery (CSRF) vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203