VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

285 CVEsRSS

CVE-2026-82647Medium· 6.1
4w ago

WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation

WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can …

▾ SunlitEPSS 0.15%via NVD
CVE-2026-82544Medium· 4.3
4w ago

A flaw has been found in wger-project wger up to 2.6.0-alpha2

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-82468Medium· 4.7
4w ago

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substring…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-17522Medium· 5.4
4w ago

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in admini…

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in admini…

▾ SunlitEPSS 0.09%via NVD
CVE-2026-81733None
1mo ago

WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php

WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, custom…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-80210Medium· 6.5
1mo ago

FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php cal…

FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php cal…

▾ SunlitFrontAccounting · FrontAccountingEPSS 0.22%via NVD
CVE-2026-48549Medium· 6.5
1mo ago

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values …

▾ SunlitEPSS 0.26%via NVD
CVE-2026-48548Medium· 6.5
1mo ago

Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent

Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST request t…

▾ SunlitEPSS 0.21%via NVD
CVE-2025-56798High· 8.8
1mo ago

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.

Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.

▾ TwilightEPSS 0.24%via NVD
CVE-2026-55532High· 7.6
1mo ago

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

▾ Twilightpraisonai · praisonaiEPSS 0.20%via OSV
CVE-2026-58003High· 7.1
1mo ago

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET requ…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-58001Medium· 5.7
1mo ago

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-57944Medium· 5.4
1mo ago

AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data

AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers c…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-66001None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-63654None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow app…

▾ SunlitEPSS 0.26%via NVD
GHSA-p2ch-c2c3-4xm5Medium· 6.1
1mo ago

Winter: CSRF through AJAX handler names reachable as backend page actions

Winter: CSRF through AJAX handler names reachable as backend page actions

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
CVE-2026-62671Medium· 5.4
1mo ago

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level GET request through the TaskServiceProvider task: URI parameter without…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-40509Medium· 4.3
1mo ago

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation against expected path formats. An attac…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-71694High· 8.8
1mo ago

An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling log…

An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling log…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-63123Medium· 6.5
1mo ago

Tina is a headless content management system

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, an…

▾ Sunlittinacms · @tinacms/cliEPSS 0.26%via NVD
CVE-2026-45129Medium· 4.6
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers to rotate a victim administrator's recovery codes with a specially crafte…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-45128Low· 3.5
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers to change a victim administrator's default user list view by embedding a s…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-45127Low· 3.5
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain requests correctly, allowing same-site attackers to create draft entries from archived entries by embedding a specially craf…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-45126Low· 3.5
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate the anti-CSRF token correctly, allowing same-site attackers to enable or disable registration challenge questions with…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-45119Medium· 4.6
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site attackers to alter table encoding and deny service with a specially craft…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-55593Medium· 6.5
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in lib/Froxlor/Ajax/Ajax.php checks only for a v…

▾ Sunlitfroxlor · froxlor/froxlorEPSS 0.26%via NVD
CVE-2026-68923Medium· 6.5
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware only in the deprecated MIDDLEWARE_CLASSES setting and omits it from the active MIDDLEWARE …

▾ Sunlitmobsf · mobsfEPSS 0.26%via NVD
CVE-2026-18165Medium· 4.2
1mo ago

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefi…

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.10%via NVD
CVE-2026-73847Medium· 6.8PoC
1mo ago

Emlog is an open source website building system

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an att…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-73482High· 8.1
1mo ago

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protecte…

▾ TwilightEPSS 0.34%via NVD
CWE-352 vulnerabilities (CVEs) — page 5 · VulnSea