CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,302 vulnerabilities with CWE-352
CVE-2026-34896
HIGH
WordPress Under Construction, Coming Soon & Maintenance Mode plugin <= 2.1.1 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 7.5
CVE-2026-35181
MEDIUM
WWBN AVideo Affected by CSRF on Player Skin Configuration via admin/playerUpdate.json.php
CVSS 4.3
CVE-2026-35180
MEDIUM
WWBN AVideo affected by CSRF on Site Customization Endpoint Enables Logo Overwrite via Base64 File Write
CVSS 4.3
CVE-2026-5624
MEDIUM
ProjectSend upload.php cross-site request forgery
CVSS 4.3
CVE-2026-5572
MEDIUM
Technostrobe HI-LED-WR120-G2 cross-site request forgery
CVSS 4.3
CVE-2026-34228
MEDIUM
Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write
CVSS 6.5
CVE-2026-34749
MEDIUM
Payload <3.79.1 Authentication Flow - CSRF Protection Bypass
CVSS 5.4
CVE-2026-5283
MEDIUM
Google Chrome <146.0.7680.178 - Info Disclosure
CVSS 6.5
CVE-2026-34613
MEDIUM
AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins
CVSS 6.5
CVE-2026-34611
MEDIUM
AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users
CVSS 6.5
CVE-2026-34394
HIGH
AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking
CVSS 8.1
CVE-2026-34384
MEDIUM
Admidio: Missing CSRF Protection on Registration Approval Actions
CVSS 4.5
CVE-2026-34383
MEDIUM
Admidio: CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter
CVSS 4.3
CVE-2026-34382
MEDIUM
Admidio: Missing CSRF Protection on Custom List Deletion in mylist_function.php
CVSS 4.6
CVE-2026-3191
MEDIUM
Minify HTML <= 2.1.12 - Cross-Site Request Forgery to Plugin Settings Update
CVSS 5.4
CVE-2026-33373
HIGH
Zimbra Collaboration 10.0-10.1 - CSRF
CVSS 8.8
CVE-2026-4315
HIGH
WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI
CVE-2026-4971
MEDIUM
SourceCodester Note Taking App cross-site request forgery
CVSS 4.3
CVE-2026-4968
MEDIUM
SourceCodester Diary App diary.php cross-site request forgery
CVSS 4.3
CVE-2026-4984
HIGH
Botpress - Credential Disclosure via Twilio Webhook Handler
CVSS 8.2
CVE-2026-4393
MEDIUM
Automated Logout - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-030
CVSS 4.3
CVE-2026-1032
MEDIUM
Conditional Menus <= 1.2.6 - Cross-Site Request Forgery to Menu Options Update
CVSS 4.3
CVE-2026-3857
HIGH
Cross-Site Request Forgery (CSRF) in GitLab
CVSS 8.1
CVE-2026-27659
MEDIUM
Mattermost <= 11.4.0 - Access Control Policy Activation CSRF
CVSS 4.6
CVE-2026-3211
MEDIUM
Theme Negotiation by Rules - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-012
CVSS 4.3
Details
Vulnerabilities
9,302
Exploit Likelihood
Medium