Vendor
Lektor versions 3.3.14 and 3.4.0b15 are vulnerable to CSRF in the admin API, allowing unauthenticated attackers to perform state-changing operations via malicious web pages.