VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

236 CVEsRSS

CVE-2026-63373Medium· 4.2
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever IS_GAE is f…

Sunlitjgraph · drawiovia NVD
CVE-2026-61687High· 7.1
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

Twilighthatchet · hatchetvia NVD
CVE-2026-94404High· 7.1
today

MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protec…

MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protec…

TwilightMISP · MISPvia NVD
CVE-2026-92410Medium· 4.3
yesterday

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in…

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in…

SunlitEPSS 0.10%via NVD
CVE-2026-93873Medium· 4.3PoC
3d ago

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from attacker-controlled pages to send forged messages attri…

TwilightCotonti · CotontiEPSS 0.16%via NVD
CVE-2026-93870Medium· 4.3
3d ago

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit POST requests to modi…

SunlitCotonti · CotontiEPSS 0.14%via NVD
CVE-2026-84084High· 8.8
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

TwilightIBM · Guardium Data ProtectionEPSS 0.18%via NVD
CVE-2026-84077High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

TwilightIBM · Guardium Data ProtectionEPSS 0.19%via NVD
CVE-2026-77568Medium· 4.2
3d ago

Mojolicious is a real-time web framework for Perl

Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in rendered HTML. When response compression is enabled and attac…

Sunlitmojolicious · mojoEPSS 0.10%via NVD
CVE-2025-15399Critical· 10.0
3d ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

MidnightIBM · Common LicensingEPSS 0.25%via NVD
CVE-2026-93531Medium· 4.3PoC
3d ago

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated re…

Twilightgedelumbung · HospitalManagementEPSS 0.22%via NVD
CVE-2026-93456High· 8.2
3d ago

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into…

Twilightbatiste · django-page-cmsEPSS 0.15%via NVD
CVE-2026-54642Medium· 5.3
4d ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the pr…

Sunlitcubecart · v6EPSS 0.22%via NVD
CVE-2026-54510High· 7.1PoC
4d ago

Speakr is a personal, self-hosted web application designed for transcribing audio recordings

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the …

Midnightmurtaza-nasir · speakrEPSS 0.14%via NVD
CVE-2026-80355Medium· 5.4
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote …

SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.21%via NVD
CVE-2026-78295High· 8.8
4d ago

Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.

TwilightXagio SEO · xagio-seoEPSS 0.14%via NVD
CVE-2026-74005Medium· 5.4
4d ago

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.

SunlitPublishPress · organize-seriesEPSS 0.10%via NVD
CVE-2026-66571High· 7.1
4d ago

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

TwilightGabe Livan · wp-asset-clean-upEPSS 0.10%via NVD
CVE-2026-91009Medium· 4.3
4d ago

The Active Woot Products Tables for WooCommerce

The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title …

SunlitEPSS 0.10%via NVD
CVE-2026-92582High· 7.1
5d ago

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global…

TwilightWWBN · AVideoEPSS 0.12%via NVD
CVE-2026-92751High· 8.1PoC
5d ago

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints l…

Midnightyahoo · CMAKEPSS 0.17%via NVD
CVE-2026-92806High· 8.1PoC
5d ago

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitr…

MidnightphpList · phpListEPSS 0.17%via NVD
CVE-2026-61593High· 8.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin …

Twilightdjust · djustEPSS 0.18%via NVD
CVE-2026-92383Medium· 4.3PoC
5d ago

A security vulnerability has been detected in PbootCMS up to 3.2.24

A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Manage…

TwilightEPSS 0.20%via NVD
CVE-2026-19535High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to …

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to …

TwilightAdvantech · EKI-1242IEIMSEPSS 0.24%via NVD
CVE-2026-40857High· 8.4
5d ago

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This…

TwilightWNC · T-Mobile 5G Box IDUEPSS 0.19%via NVD
CVE-2026-87860Medium· 4.3
5d ago

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a…

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a…

SunlitEPSS 0.14%via NVD
CVE-2026-85131Medium· 6.5
5d ago

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict the targeted items to its own records, allowing attackers…

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict the targeted items to its own records, allowing attackers…

SunlitEPSS 0.18%via NVD
CVE-2026-76856High· 8.1
6d ago

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to trick authenticate…

TwilightNetcore · NR255-VEPSS 0.16%via NVD
CVE-2026-83126High· 7.6
6d ago

Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with …

TwilightOracle Corporation · Oracle Sales OnlineEPSS 0.28%via NVD
CWE-352 vulnerabilities (CVEs) · VulnSea