VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

285 CVEsRSS

CVE-2026-87449Medium· 4.3⚖ disputed
2w ago

Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-9215Medium· 6.7
2w ago

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations …

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations …

▾ Sunlitnetgear · xr1000_firmwareEPSS 0.19%via NVD
CVE-2026-86718High· 7.1PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by maki…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by maki…

▾ MidnightWWBN · AVideoEPSS 0.20%via NVD
CVE-2026-86724Medium· 6.5
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session…

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session…

▾ SunlitWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-86719Medium· 5.4
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id fro…

▾ SunlitWWBN · AVideoEPSS 0.14%via NVD
CVE-2026-86135High· 7.0
2w ago

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a …

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a …

▾ TwilightWatchGuard · DimensionEPSS 0.25%via NVD
CVE-2026-33920Low· 3.5
2w ago

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker with a valid account can trick a victim into unknowingly authenti…

▾ SunlitNozomi Networks · GuardianEPSS 0.13%via NVD
CVE-2026-76961Low· 3.5
2w ago

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticate…

▾ SunlitSAP_SE · SAP S/4HANA (Finance for Advanced Payment Management)EPSS 0.14%via NVD
CVE-2026-76960Low· 3.5
2w ago

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticate…

▾ SunlitSAP_SE · SAP S/4HANA (Finance for Advanced Payment Management)EPSS 0.14%via NVD
CVE-2026-76959Medium· 4.6
2w ago

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated…

▾ SunlitSAP_SE · SAP S/4HANA (Finance for Advanced Payment Management)EPSS 0.13%via NVD
CVE-2026-86307Medium· 4.3PoC
2w ago

A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930

A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.…

▾ Twilightlight0011 · cmsEPSS 0.23%via NVD
CVE-2026-86281Medium· 4.3PoC
2w ago

A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be ini…

▾ TwilightSourceCodester · Syllabus-Aligned Learning Management & Examination SystemEPSS 0.23%via NVD
CVE-2026-86182Medium· 4.3PoC
3w ago

A vulnerability was determined in diem-project diem up to 5.1.3

A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument…

▾ Twilightdiem-project · diemEPSS 0.23%via NVD
CVE-2026-52777Critical· 9.4
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.

▾ MidnightYesWiki · yeswikiEPSS 0.28%via NVD
CVE-2026-82911None
3w ago

Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by…

Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-85547None
3w ago

A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified as a REST request. MISP's REST detection can be influenced by …

A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified as a REST request. MISP's REST detection can be influenced by …

▾ SunlitEPSS 0.36%via NVD
CVE-2026-85546High· 8.6
3w ago

MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality

MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method v…

▾ Twilightmisp · mispEPSS 0.21%via NVD
CVE-2026-82712High· 8.8
3w ago

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-53760Medium· 5.2PoC
3w ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because…

▾ TwilightAdmidio · admidioEPSS 0.17%via NVD
CVE-2026-85162Medium· 6.5
3w ago

AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections

AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to overwrite authen…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-85161Medium· 4.3
3w ago

AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks

AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' …

▾ SunlitEPSS 0.15%via NVD
CVE-2026-85236High· 8.8
3w ago

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are no…

▾ Twilightmisp-project · mispEPSS 0.25%via NVD
CVE-2026-49455Medium· 6.5
3w ago

Waku is the minimal React framework

Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. A cross-origin web attacker can therefore cause …

▾ Sunlitwaku · wakuEPSS 0.17%via NVD
CVE-2026-53649Critical· 9.6
3w ago

Joro is a web exploitation framework

Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelis…

▾ MidnightBishopFox · github.com/BishopFox/joroEPSS 0.33%via NVD
CVE-2026-73780High· 8.3
3w ago

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input again…

▾ Twilighthpe · arubaos-cxEPSS 0.20%via NVD
CVE-2026-83595High· 8.1
3w ago

AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection

AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser…

▾ TwilightEPSS 0.23%via NVD
CVE-2026-19418High
3w ago

TYPO3 CMS - Broken Access Control in Backend and Install Tool

TYPO3 CMS - Broken Access Control in Backend and Install Tool

▾ Twilighttypo3 · typo3/cms-backendEPSS 0.24%via GHSA
CVE-2026-54599None
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-81890Medium· 5.4
3w ago

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken(…

▾ Sunlitstudio-42 · studio-42/elfinderEPSS 0.18%via NVD
CVE-2026-81888Medium· 5.4
3w ago

@hono/oauth-providers is Authentication middleware for Hono

@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a ca…

▾ Sunlithono · @hono/oauth-providersEPSS 0.19%via NVD
CWE-352 vulnerabilities (CVEs) — page 4 · VulnSea