CWE-352
CVEs classified under CWE-352, newest first.
286 CVEsRSS
CVE-2026-16216Medium· 4.3A weakness has been identified in geex-arts django-jet up to 1.0.8
A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote.…
CVE-2026-16081Medium· 4.3A vulnerability was determined in Sipeed PicoClaw up to 0.2.9
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched r…
CVE-2026-9734Medium· 4.3The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it po…
CVE-2026-38057High· 8.1ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote att…
CVE-2026-15080NoneCross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery. This issue affects Ray Enterprise Translation versions: from 0.0.0 to 4.0.4, from 4.1.0 to 4.1.4, from 11.0.0 to 11.0.4.
CVE-2026-13243NoneCross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue affects Salesforce Suite versions: from 0.0.0 to 5.1.3.
CVE-2026-59148High· 8.8PoCMockoon provides way to design and run mock APIs
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runti…
CVE-2026-49471High· 8.3Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
GHSA-q855-8rh5-jfgqMedium· 6.5ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
CVE-2026-44342Medium· 5.3New API is vulnerable to CSRF through user email binding
New API is vulnerable to CSRF through user email binding
CVE-2026-59713High· 8.1Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters
Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization code…
CVE-2026-14620Medium· 4.7PoCwebpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the …
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the …
CVE-2026-13537Medium· 4.3A vulnerability was found in CodeAstro Human Resource Management System 1.0
A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public a…
CVE-2026-57306Medium· 4.2Jenkins Zowe zDevOps Plugin has a CSRF vulnerability
Jenkins Zowe zDevOps Plugin has a CSRF vulnerability
CVE-2026-57305Medium· 5.4Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
CVE-2026-12986HighPayara Server Full has a Cross-Site Request Forgery vulnerability
Payara Server Full has a Cross-Site Request Forgery vulnerability
CVE-2026-57295Medium· 5.4Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability
Jenkins EC2 Fleet Plugin has a cross-site request forgery (CSRF) vulnerability
CVE-2026-57292Medium· 5.4Jenkins Gitee Plugin has a cross-site request forgery vulnerability
Jenkins Gitee Plugin has a cross-site request forgery vulnerability
CVE-2026-57290Medium· 4.3Jenkins Priority Sorter Plugin has a CSRF vulnerability
Jenkins Priority Sorter Plugin has a CSRF vulnerability
CVE-2026-57298Medium· 5.4Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability
Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability
CVE-2026-57283Medium· 4.3Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability
Jenkins Pipeline: Groovy Plugin has a CSRF vulnerability
CVE-2026-52800High· 8.8Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
CVE-2026-50132High· 7.3Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
CVE-2026-49215Lowsymfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
GHSA-mxjx-28vx-xjjjMedium· 5.9Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
GHSA-v3f4-w7r7-v3hmHighUni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
CVE-2026-55741High· 8.8Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data vi…
CVE-2026-55744High· 8.1Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
CVE-2026-55742Critical· 9.6Cotonti: Cross-Site Request Forgery in the administration rights handler
Cotonti: Cross-Site Request Forgery in the administration rights handler
CVE-2026-55745Medium· 5.4Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module