VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

237 CVEsRSS

CVE-2026-83126High· 7.6
6d ago

Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with …

TwilightOracle Corporation · Oracle Sales OnlineEPSS 0.28%via NVD
CVE-2026-18425Low· 2.7
6d ago

Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before upda…

Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemapUpdate) using only the global access_sitemap task permission and did not check per-page edit permission before upda…

Sunlitconcretecms · concrete_cmsEPSS 0.18%via NVD
CVE-2026-81924Medium· 6.5⚖ disputed
6d ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-suppl…

Sunlitconcretecms · concrete_cmsEPSS 0.20%via NVD
CVE-2026-81920Medium· 4.3⚖ disputed
6d ago

Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page

Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did no…

Sunlitconcretecms · concrete_cmsEPSS 0.13%via NVD
CVE-2026-78081High· 7.1
6d ago

Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A forged request riding a victim's active checkout session could silently overwri…

Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A forged request riding a victim's active checkout session could silently overwri…

Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.15%via NVD
CVE-2026-68532Low· 2.3
6d ago

Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery

Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type manage…

SunlitConcrete CMS · Concrete CMSEPSS 0.21%via NVD
CVE-2026-81919Medium· 4.3⚖ disputed
6d ago

Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks)

Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization but performed no…

Sunlitconcretecms · concrete_cmsEPSS 0.11%via NVD
CVE-2026-81897Medium· 5.4⚖ disputed
6d ago

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote a…

Sunlitconcretecms · concrete_cmsEPSS 0.11%via NVD
CVE-2026-91857Medium· 5.3
6d ago

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist()  …

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist()  …

SunlitMISP · MISPEPSS 0.17%via NVD
CVE-2026-91819Medium· 6.9
6d ago

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request…

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request…

SunlitMISP · MISPEPSS 0.16%via NVD
CVE-2026-52823Medium· 5.3
6d ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing o…

Sunlitkimai · kimaiEPSS 0.21%via NVD
CVE-2026-81902High· 8.1
1w ago

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks)

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on t…

Twilightconcretecms · concrete_cmsEPSS 0.16%via NVD
CVE-2026-17047Medium· 5.4
1w ago

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

SunlitIBM · Db2 Mirror for iEPSS 0.12%via NVD
CVE-2026-90893Medium· 5.1
1w ago

MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController

MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which di…

SunlitMISP · MISPEPSS 0.18%via NVD
CVE-2026-82764Medium· 4.3
1w ago

Cross-site request forgery vulnerability exists in multiple Contec products

Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.

SunlitContec Co., Ltd. · FXA5000EPSS 0.15%via NVD
CVE-2026-90599Medium· 4.3PoC
1w ago

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forg…

TwilightRizwan17 · inventory-management-systemEPSS 0.16%via NVD
CVE-2026-84024Medium· 4.3
1w ago

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

SunlitEPSS 0.10%via NVD
CVE-2026-84023Medium· 6.5
1w ago

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafte…

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafte…

SunlitEPSS 0.11%via NVD
CVE-2026-81429High· 7.1
1w ago

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to …

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to …

TwilightEPSS 0.09%via NVD
CVE-2026-81090High· 7.2
1w ago

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP v…

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP v…

TwilightEPSS 0.27%via NVD
CVE-2026-77006Critical· 9.6
1w ago

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user…

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user…

MidnightEPSS 0.18%via NVD
CVE-2026-81907Medium· 6.1
1w ago

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

SunlitConcrete CMS · Concrete CMSEPSS 0.21%via NVD
CVE-2026-68526Medium· 5.3
1w ago

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

SunlitConcrete CMS · Concrete CMSEPSS 0.18%via NVD
CVE-2026-50025Medium· 6.9
1w ago

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN prove…

Sunlitt-mart · mouseholeEPSS 0.18%via NVD
CVE-2026-89245Medium· 6.5PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can cra…

TwilightWWBN · AVideoEPSS 0.15%via NVD
CVE-2026-62139Medium· 4.3
1w ago

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

SunlitGoogle · google-site-kitEPSS 0.10%via NVD
CVE-2026-81912Medium· 5.7
1w ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, s…

SunlitConcrete CMS · Concrete CMSEPSS 0.18%via NVD
CVE-2026-62133Medium· 5.4
1w ago

WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability

Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.

Sunlitrometheme · rometheme-for-elementorEPSS 0.13%via CVEORG
CVE-2026-89148Medium· 5.4PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequ…

TwilightWWBN · AVideoEPSS 0.15%via NVD
CVE-2026-49992Medium· 6.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exp…

Sunlitkimai · kimaiEPSS 0.16%via NVD
CWE-352 vulnerabilities (CVEs) — page 2 · VulnSea