VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

288 CVEsRSS

CVE-2026-55742Critical· 9.6
3mo ago

Cotonti: Cross-Site Request Forgery in the administration rights handler

Cotonti: Cross-Site Request Forgery in the administration rights handler

▾ Midnightcotonti · cotonti/cotontiEPSS 0.21%via GHSA
CVE-2026-55745Medium· 5.4
3mo ago

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module

▾ Sunlitcotonti · cotonti/cotontiEPSS 0.14%via GHSA
CVE-2026-53663Low· 3.1
3mo ago

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

▾ Sunlitreact-router · react-routerEPSS 0.15%via GHSA
CVE-2026-48147Medium· 6.5
3mo ago

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

▾ Sunlitbudibase · @budibase/backend-coreEPSS 0.17%via GHSA
CVE-2025-58468High· 8.8
3mo ago

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerabi…

▾ Twilightqnap · notification_centerEPSS 0.16%via NVD
CVE-2026-49396High· 7.1
3mo ago

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents

▾ Twilightnezhahq · github.com/nezhahq/nezhaEPSS 0.17%via GHSA
CVE-2026-47725High
3mo ago

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.22%via GHSA
CVE-2026-41074High· 7.1
4mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-22880Medium· 6.1
4mo ago

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credenti…

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credenti…

▾ Sunlitmattermost · mattermost_mobileEPSS 0.12%via NVD
CVE-2026-44925High· 8.8
4mo ago

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VI…

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VI…

▾ Twilightveritas · infoscale_operations_managerEPSS 0.22%via NVD
CVE-2026-8604High· 8.8
4mo ago

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

▾ Twilightscadabr · scadabrEPSS 0.21%via NVD
CVE-2026-40703Medium· 5.4
4mo ago

A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

▾ SunlitEPSS 0.14%via NVD
CVE-2026-39848Medium· 6.5
5mo ago

Dockyard is a Docker container management app

Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to requ…

▾ Sunlit10ij · dockyardEPSS 0.15%via NVD
CVE-2026-0811Medium· 5.4
5mo ago

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' func…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-4401Medium· 5.4
5mo ago

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.php` in all versions up to, and including, 5.1.10. This is…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-5918Medium· 4.3
5mo ago

Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page

Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.21%via NVD
CVE-2026-1673Medium· 4.3
5mo ago

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validatio…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-1672Medium· 6.5
5mo ago

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validatio…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-5624Medium· 4.3
5mo ago

A security flaw has been discovered in ProjectSend r2002

A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit …

▾ SunlitEPSS 0.23%via NVD
CVE-2016-20054Medium· 4.3
5mo ago

Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms

Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administrators into submitting requests to adm…

▾ Sunlitnodcms · nodcmsEPSS 0.11%via NVD
CVE-2016-20053Medium· 5.3
5mo ago

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft H…

▾ Sunlitredaxo · redaxoEPSS 0.15%via NVD
CVE-2016-20051Medium· 5.3
5mo ago

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms

Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into vi…

▾ Sunlitsnewscms · snewsEPSS 0.16%via NVD
CVE-2026-3191Medium· 5.4
6mo ago

The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12

The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This makes it…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-4315Medium· 6.5
6mo ago

A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into v…

A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into v…

▾ Sunlitwatchguard · firewareEPSS 0.24%via NVD
CVE-2026-4984High· 8.2
6mo ago

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include …

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include …

▾ Twilightbotpress · botpressEPSS 0.18%via NVD
CVE-2026-29113Medium· 4.3
6mo ago

Craft is a content management system (CMS)

Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action …

▾ Sunlitcraftcms · craft_cmsEPSS 0.18%via NVD
CVE-2026-1468None
6mo ago

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does …

▾ SunlitEPSS 0.22%via NVD
CVE-2026-27609Medium· 6.5
7mo ago

Parse Dashboard is a standalone dashboard for managing Parse Server apps

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) lacks CSRF protection. An attacker can craft a malicious pa…

▾ SunlitEPSS 0.18%via NVD
CVE-2025-12821High· 8.8
7mo ago

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes i…

▾ Twilightspicethemes · NewsBloggerEPSS 0.35%via NVD
CVE-2026-23950High· 8.8
8mo ago

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalizatio…

▾ Twilightisaacs · tarEPSS 0.26%via NVD
CWE-352 vulnerabilities (CVEs) — page 8 · VulnSea