CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
8,791 results Clear all
CVE-2026-31954 NONE 1 PoC Analysis
Emlog <=2.6.6 - CSRF
Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.
CWE-352 Mar 11, 2026
CVE-2026-30868 6.3 MEDIUM
OPNsense <26.1.4 - CSRF
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but are accessible via HTTP GET requests without CSRF protection. The framework CSRF validation in ApiControllerBase only applies to POST/PUT/DELETE methods, allowing authenticated GET requests to bypass CSRF verification. As a result, a malicious website can trigger privileged backend actions when visited by an authenticated user, causing unintended service reloads and configuration changes through configd. This results in an authenticated Cross‑Site Request Forgery vulnerability allowing unauthorized system state changes. This vulnerability is fixed in 26.1.4.
CWE-352 Mar 11, 2026
CVE-2026-3903 4.3 MEDIUM EPSS 0.00
Modular DS WordPress Plugin <2.5.1 - CSRF
The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing nonce validation on the postConfirmOauth() function. This makes it possible for unauthenticated attackers to disconnect the plugin's OAuth/SSO connection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Mar 11, 2026
CVE-2026-2626 8.1 HIGH EPSS 0.00
Divi-Booster <5.0.2 - CSRF & Object Injection
The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be further exploited when combined with a PHP gadget chain to achieve PHP Object Injection
CWE-502 Mar 11, 2026
CVE-2026-2324 6.1 MEDIUM EPSS 0.00
LatePoint Calendar Booking Plugin <5.2.7 - CSRF
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.7. This is due to missing or incorrect nonce validation on the reload_preview() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Mar 11, 2026
CVE-2026-29113 1 Writeup EPSS 0.00
Craft CMS <4.17.4/5.9.7 - CSRF
Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce a CSRF token, an attacker can force a logged-in victim editor to mint a preview token chosen by the attacker. That token can then be used by the attacker (without authentication) to access previewed/unpublished content tied to the victim’s authorized preview scope. This vulnerability is fixed in 4.17.4 and 5.9.7.
CWE-352 Mar 10, 2026
CVE-2026-28495 9.6 CRITICAL EPSS 0.00
GetSimple CMS 3.3.22 - CSRF to RCE
GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code via the gsconfig editor module. The form lacks CSRF protection, enabling a remote unauthenticated attacker to exploit this via Cross-Site Request Forgery against a logged-in admin, achieving Remote Code Execution (RCE) on the web server.
CWE-352 Mar 10, 2026
CVE-2026-28281 7.1 HIGH EPSS 0.00
InstantCMS <2.18.1 - CSRF
InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests on behalf of the user. This vulnerability is fixed in 2.18.1.
CWE-352 Mar 10, 2026
CVE-2026-1508 4.3 MEDIUM EPSS 0.00
Court Reservation <1.10.9 - CSRF
The Court Reservation WordPress plugin before 1.10.9 does not have CSRF check in place when deleting events, which could allow attackers to make a logged in admin delete them via a CSRF attack
CWE-352 Mar 10, 2026
CVE-2025-70031 8.8 HIGH EPSS 0.00
Sunbird-Ed SunbirdEd-portal 1.13.4 - CSRF
An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
CWE-352 Mar 09, 2026
CVE-2026-3770 4.3 MEDIUM EPSS 0.00
SourceCodester CLMS 1.0 - CSRF
A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.
CWE-862 Mar 08, 2026
CVE-2026-29784 7.5 HIGH 1 Writeup EPSS 0.00
Ghost 5.101.6-6.19.2 - CSRF
Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the requesting session. In some scenarios this might have made it easier for phishers to take over a Ghost site. This issue has been patched in version 6.19.3.
CWE-352 Mar 07, 2026
CVE-2026-1087 4.3 MEDIUM EPSS 0.00
Guardian News Feed Plugin <1.2 - CSRF
The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the Guardian API key, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Mar 07, 2026
CVE-2026-1086 4.3 MEDIUM EPSS 0.00
WordPress Font Pairing Preview - CSRF
The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Mar 07, 2026
CVE-2026-1085 4.3 MEDIUM EPSS 0.00
True Ranker WordPress Plugin <2.2.9 - CSRF
The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.9. This is due to missing nonce validation on the seolocalrank-signout action. This makes it possible for unauthenticated attackers to disconnect the administrator's True Ranker account via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Mar 07, 2026
CVE-2026-1073 4.3 MEDIUM EPSS 0.00
Purchase Button For Affiliate Link <1.0.2 - CSRF
The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing nonce validation on the settings page form handler in `inc/purchase-btn-options-page.php`. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Mar 07, 2026
CVE-2026-2494 4.3 MEDIUM EPSS 0.00
ProfileGrid WordPress Plugin <=5.9.8.2 - CSRF
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it possible for unauthenticated attackers to approve or deny group membership requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Mar 07, 2026
CVE-2026-1644 4.3 MEDIUM EPSS 0.00
WP Frontend Profile <1.3.8 - CSRF
The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing nonce validation on the 'update_action' function. This makes it possible for unauthenticated attackers to approve or reject user account registrations via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
CWE-352 Mar 07, 2026
CVE-2018-25200 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
OOP CMS BLOG 1.0 - CSRF
OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by crafting malicious POST requests. Attackers can submit forms to the addUser.php endpoint with parameters including userName, password, email, and role set to administrative privileges to gain unauthorized access.
CWE-352 Mar 06, 2026
CVE-2018-25190 5.3 MEDIUM 1 PoC Analysis EPSS 0.00
Easyndexer 1.0 - CSRF
Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative accounts by submitting forged POST requests. Attackers can craft malicious web pages that submit POST requests to createuser.php with parameters including username, password, name, surname, and privileges set to 1 for administrator access.
CWE-352 Mar 06, 2026