Medium severity5.4NVD Advisory· Published Jan 22, 2026· Updated Apr 28, 2026
CVE-2026-24384
CVE-2026-24384
Description
Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14.
Affected products
1- Range: <=2.14
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.