VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

285 CVEsRSS

CVE-2026-52823Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing o…

▾ Sunlitkimai · kimaiEPSS 0.30%via NVD
CVE-2026-81902High· 8.1
1w ago

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks)

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on t…

▾ Twilightconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-17047Medium· 5.4
1w ago

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

▾ SunlitIBM · Db2 Mirror for iEPSS 0.12%via NVD
CVE-2026-90893Medium· 5.1
1w ago

MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController

MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which di…

▾ SunlitMISP · MISPEPSS 0.26%via NVD
CVE-2026-82764Medium· 4.3
1w ago

Cross-site request forgery vulnerability exists in multiple Contec products

Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.

▾ SunlitContec Co., Ltd. · FXA5000EPSS 0.19%via NVD
CVE-2026-90599Medium· 4.3PoC
2w ago

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forg…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.24%via NVD
CVE-2026-84024Medium· 4.3
2w ago

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

▾ SunlitEPSS 0.14%via NVD
CVE-2026-84023Medium· 6.5
2w ago

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafte…

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafte…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-81429High· 7.1
2w ago

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to …

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to …

▾ TwilightEPSS 0.13%via NVD
CVE-2026-81090High· 7.2
2w ago

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP v…

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP v…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-77006Critical· 9.6
2w ago

The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user,…

The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user,…

▾ MidnightEPSS 0.25%via NVD
CVE-2026-81907High· 7.1
2w ago

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

▾ Twilightconcretecms · concrete_cmsEPSS 0.14%via NVD
CVE-2026-68526Medium· 4.3
2w ago

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-50025Medium· 6.9
2w ago

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN prove…

▾ Sunlitt-mart · mouseholeEPSS 0.26%via NVD
CVE-2026-89245Medium· 6.5PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can cra…

▾ TwilightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-62139Medium· 4.3
2w ago

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

▾ SunlitGoogle · google-site-kitEPSS 0.10%via NVD
CVE-2026-81912Medium· 5.7
2w ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, s…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.19%via NVD
CVE-2026-62133Medium· 5.4
2w ago

WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability

Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.

▾ Sunlitrometheme · rometheme-for-elementorEPSS 0.14%via CVEORG
CVE-2026-89148Medium· 5.4PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequ…

▾ TwilightWWBN · AVideoEPSS 0.16%via NVD
CVE-2026-49992Medium· 6.3
2w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exp…

▾ Sunlitkimai · kimaiEPSS 0.22%via NVD
CVE-2026-84432Medium· 5.3
2w ago

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a board_slot_proxy Block and disp…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.24%via NVD
CVE-2026-88872High· 7.1PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sendin…

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sendin…

▾ MidnightWWBN · AVideoEPSS 0.19%via NVD
CVE-2026-80380High· 7.1
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.20%via NVD
CVE-2026-88061Medium· 5.8
2w ago

career-ops is an open-source AI-assisted job search and application management tool

career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or …

▾ Sunlitsantifer · career-opsEPSS 0.38%via NVD
CVE-2026-88871Medium· 4.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script …

▾ TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-78084Medium· 6.9
2w ago

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file remo…

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.33%via CVEORG
CVE-2026-78083High· 7.1
2w ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) end…

▾ Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.21%via CVEORG
CVE-2026-88873High· 7.1
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests …

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests …

▾ TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-88870High· 7.1
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can craft malicious pages wit…

▾ TwilightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-82184Medium· 5.3
2w ago

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to …

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to …

▾ SunlitEPSS 0.16%via NVD
CWE-352 vulnerabilities (CVEs) — page 3 · VulnSea