VulnSea

CWE-352

CVEs classified under CWE-352, newest first.

288 CVEsRSS

CVE-2025-31054High· 7.1
9mo ago

Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from n/a through 2.0.8.

Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from n/a through 2.0.8.

▾ TwilightEPSS 0.11%via NVD
CVE-2025-34430Medium· 4.3
9mo ago

1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality

1Panel versions 1.10.33 through 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the panel name management functionality. The affected endpoint does not implement CSRF defenses such as anti-CSRF tokens or Origin/Refere…

▾ Sunlitfit2cloud · 1panelEPSS 0.21%via NVD
CVE-2025-34429High· 7.1
9mo ago

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-change endpoint lacks CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. A…

▾ Twilightfit2cloud · 1panelEPSS 0.18%via NVD
CVE-2025-34410High· 7.1
9mo ago

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel)

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the settings panel (/settings/panel). The endpoint does not implement CSRF protections such as…

▾ Twilightfit2cloud · 1panelEPSS 0.16%via NVD
CVE-2025-12879High· 8.8
9mo ago

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce validation in the "Import Using CSV File" function. This makes it possib…

▾ TwilightEPSS 0.18%via NVD
CVE-2025-12128Medium· 4.3
9mo ago

The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7

The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7. This is due to missing or incorrect nonce validation on the save_data_hcps() funct…

▾ SunlitEPSS 0.12%via NVD
CVE-2025-10055Medium· 4.3
9mo ago

The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3

The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on several endpoints. This makes it possible for unauthent…

▾ SunlitEPSS 0.12%via NVD
CVE-2025-13362Medium· 4.3
9mo ago

The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3

The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthent…

▾ SunlitEPSS 0.15%via NVD
CVE-2024-45538Critical· 9.6
9mo ago

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute …

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute …

▾ Midnightsynology · diskstation_managerEPSS 0.37%via NVD
CVE-2025-65027High· 7.6PoC
9mo ago

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malic…

▾ Midnightromm.app · rommEPSS 0.33%via NVD
CVE-2025-13871High· 8.8
9mo ago

Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication.

Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication.

▾ Twilightobjectplanet · opinioEPSS 0.18%via NVD
CVE-2024-53684High· 7.5
10mo ago

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to …

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.24%via NVD
CVE-2025-13790Medium· 4.3
10mo ago

A vulnerability was determined in Scada-LTS up to 2.7.8.1

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be ut…

▾ Sunlitscada-lts · scada-ltsEPSS 0.26%via NVD
CVE-2025-62593CriticalCISA KEVPoC
10mo ago

Ray is an AI compute engine

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…

▾ Hadalray · rayEPSS 62%via NVD
CVE-2025-9890High· 8.8
11mo ago

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible fo…

▾ TwilightEPSS 0.40%via NVD
CVE-2025-60956High· 8.0
11mo ago

Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and …

Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and …

▾ Twilightendruntechnologies · sonoma_d12_firmwareEPSS 0.20%via NVD
CVE-2025-9891Medium· 4.3
1y ago

The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2

The User Sync – Remote User Sync plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing or incorrect nonce validation on the mo_user_sync_form_handler() functi…

▾ SunlitEPSS 0.20%via NVD
CVE-2025-9629Medium· 4.3
1y ago

The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0

The USS Upyun plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on the uss_setting_page function when processing the uss_set…

▾ SunlitEPSS 0.17%via NVD
CVE-2025-10188Medium· 5.4
1y ago

The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4

The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation on the bulk_remove() function. T…

▾ SunlitEPSS 0.13%via NVD
CVE-2025-5521Medium· 4.3
1y ago

A vulnerability was found in WuKongOpenSource WukongCRM 9.0

A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/user/updataPassword. The manipulation leads to cross-site re…

▾ Sunlit5kcrm · wukong_crmEPSS 0.31%via NVD
CVE-2025-25137Medium· 6.5
1y ago

Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forgery. This issue affects Social Links: from n/a through 1.0.11.

Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forgery. This issue affects Social Links: from n/a through 1.0.11.

▾ SunlitEPSS 0.15%via NVD
CVE-2024-21202Medium· 6.1
1y ago

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology)

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated…

▾ Sunlitoracle · peoplesoft_enterprise_peopletoolsEPSS 0.20%via NVD
CVE-2024-41597Medium· 4.2
2y ago

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus…

▾ Sunlitprocesswire · processwireEPSS 0.21%via NVD
CVE-2024-3824Medium· 5.5
2y ago

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

▾ Sunlitmranderson · base64_encoder/decoderEPSS 0.20%via NVD
CVE-2024-3823Low· 2.4
2y ago

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads v…

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads v…

▾ Sunlitmranderson · base64_encoder/decoderEPSS 0.22%via NVD
CVE-2024-0830Medium· 4.3
2y ago

The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0

The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0. This is due to missing or incorrect nonce validation on several ajax actions. Th…

▾ Sunlitnajeebmedia · comments_extra_fields_for_post,_pages_and_cptEPSS 0.30%via NVD
CVE-2024-24702Medium· 4.3
2y ago

Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.

Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.

▾ Sunlitsivel · page_restrictEPSS 0.23%via NVD
CVE-2018-14519Medium· 4.3
4y ago

An issue was discovered in Kirby 2.5.12

An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page.

▾ Sunlitgetkirby · kirbyEPSS 0.49%via NVD
CVE-2017-20120Medium· 4.3
4y ago

A vulnerability classified as problematic was found in TrueConf Server 4.3.7

A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated rem…

▾ Sunlittrueconf · trueconf_serverEPSS 0.49%via NVD
CVE-2022-26173High· 8.8
4y ago

JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

▾ Twilightjforum · jforumEPSS 0.71%via NVD
CWE-352 vulnerabilities (CVEs) — page 9 · VulnSea