VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

286 CVEsRSS

CVE-2026-16216Medium· 4.3
2mo ago

A weakness has been identified in geex-arts django-jet up to 1.0.8

A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote.…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-16081Medium· 4.3
2mo ago

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched r…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-9734Medium· 4.3
2mo ago

The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0

The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it po…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-38057High· 8.1
2mo ago

ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote att…

▾ TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.31%via CVEORG
CVE-2026-15080None
2mo ago

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4.

▾ SunlitEPSS 0.14%via NVD
CVE-2026-13243None
2mo ago

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3.

▾ SunlitEPSS 0.12%via NVD
CVE-2026-59148High· 8.8PoC
2mo ago

Mockoon provides way to design and run mock APIs

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runti…

▾ Midnightmockoon · mockoonEPSS 0.26%via NVD
CVE-2026-49471High· 8.3
2mo ago

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

▾ Twilightserena-agent · serena-agentEPSS 0.37%via GHSA
GHSA-q855-8rh5-jfgqMedium· 6.5
2mo ago

ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path

ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path

▾ Sunlitha-mcp · ha-mcpvia GHSA
CVE-2026-44342Medium· 5.3
2mo ago

New API is vulnerable to CSRF through user email binding

New API is vulnerable to CSRF through user email binding

▾ SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.19%via GHSA
CVE-2026-59713High· 8.1
2mo ago

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization code…

▾ TwilightLeantime · LeantimeEPSS 0.23%via NVD
CVE-2026-14620Medium· 4.7PoC
2mo ago

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the …

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the …

▾ TwilightEPSS 0.52%via NVD
CVE-2026-13537Medium· 4.3
3mo ago

A vulnerability was found in CodeAstro Human Resource Management System 1.0

A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public a…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-57306Medium· 4.2
3mo ago

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

Jenkins Zowe zDevOps Plugin has a CSRF vulnerability

▾ Sunlitjenkins · io.jenkins.plugins:zdevopsEPSS 0.18%via GHSA
CVE-2026-57305Medium· 5.4
3mo ago

Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability

Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability

▾ Sunlitjenkins-ci · org.jenkins-ci.plugins:assemblaEPSS 0.22%via GHSA
CVE-2026-12986High
3mo ago

Payara Server Full has a Cross-Site Request Forgery vulnerability

Payara Server Full has a Cross-Site Request Forgery vulnerability

▾ Twilightpayara · fish.payara.distributions:payaraEPSS 0.27%via GHSA
CVE-2026-57295Medium· 5.4
3mo ago

Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability

Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability

▾ Sunlitamazon · com.amazon.jenkins.fleet:ec2-fleetEPSS 0.22%via GHSA
CVE-2026-57292Medium· 5.4
3mo ago

Jenkins Gitee Plugin has a cross-site request forgery vulnerability

Jenkins Gitee Plugin has a cross-site request forgery vulnerability

▾ Sunlitjenkins-ci · org.jenkins-ci.plugins:giteeEPSS 0.14%via GHSA
CVE-2026-57290Medium· 4.3
3mo ago

Jenkins Priority Sorter Plugin has a CSRF vulnerability

Jenkins Priority Sorter Plugin has a CSRF vulnerability

▾ Sunlitjenkins-ci · org.jenkins-ci.plugins:PrioritySorterEPSS 0.25%via GHSA
CVE-2026-57298Medium· 5.4
3mo ago

Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability

Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability

▾ Sunlitjenkins-ci · org.jenkins-ci.plugins:contrast-continuous-application-securityEPSS 0.14%via GHSA
CVE-2026-57283Medium· 4.3
3mo ago

Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability

Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability

▾ Sunlitjenkins · io.jenkins.plugins:pipeline-groovy-libEPSS 0.24%via GHSA
CVE-2026-52800High· 8.8
3mo ago

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

Gogs Vulnerable to CSRF Leading to Organization Owner Takeover

▾ Twilightgogs · gogs.io/gogsEPSS 0.25%via GHSA
CVE-2026-50132High· 7.3
3mo ago

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

▾ Twilightbudibase · @budibase/serverEPSS 0.19%via GHSA
CVE-2026-49215Low
3mo ago

symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted

symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.18%via GHSA
GHSA-mxjx-28vx-xjjjMedium· 5.9
3mo ago

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-v3f4-w7r7-v3hmHigh
3mo ago

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

▾ Twilightzenalexa · @zenalexa/uniclivia GHSA
CVE-2026-55741High· 8.8
3mo ago

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data vi…

▾ TwilightEPSS 0.21%via NVD
CVE-2026-55744High· 8.1
3mo ago

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

▾ Twilightcotonti · cotonti/cotontiEPSS 0.20%via GHSA
CVE-2026-55742Critical· 9.6
3mo ago

Cotonti: Cross-Site Request Forgery in the administration rights handler

Cotonti: Cross-Site Request Forgery in the administration rights handler

▾ Midnightcotonti · cotonti/cotontiEPSS 0.21%via GHSA
CVE-2026-55745Medium· 5.4
3mo ago

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

▾ Sunlitcotonti · cotonti/cotontiEPSS 0.14%via GHSA
CWE-352 vulnerabilities (CVEs) — page 7 · VulnSea