CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,302 vulnerabilities with CWE-352
CVE-2026-29839
HIGH
DedeCMS v5.7.118 - Cross-Site Request Forgery in sys_task_add.php
CVSS 8.8
CVE-2026-33252
HIGH
MCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without Authorizatrion
CVSS 7.1
CVE-2026-33649
HIGH
AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification
CVSS 8.1
CVE-2026-33507
HIGH
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
CVSS 8.8
CVE-2026-4590
LOW
kalcaddle kodbox loginSubmit API index.class.php cross-site request forgery
CVSS 3.1
CVE-2026-31849
MEDIUM
Missing CSRF protection on state-changing endpoints in Nexxt Nebula 300+
CVSS 6.5
CVE-2026-4143
MEDIUM
Neos Connector for Fakturama <= 0.0.14 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-3332
MEDIUM
Xhanch - My Advanced Settings <= 1.1.2 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-3331
MEDIUM
Lobot Slider Administrator <= 0.6.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-2723
MEDIUM
Post Snippits <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update
CVSS 6.1
CVE-2026-1503
MEDIUM
login_register <= 1.2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVSS 4.3
CVE-2026-1393
MEDIUM
Add Google Social Profiles to Knowledge Graph Box <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1392
MEDIUM
SR WP Minify HTML <= 2.1 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1390
MEDIUM
Redirect countdown <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1378
MEDIUM
WP Posts Re-order <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-32989
HIGH
Precurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file upload
CVSS 8.8
CVE-2026-33372
MEDIUM
Zimbra Collaboration 10.0-10.1 - CSRF
CVSS 5.4
CVE-2026-32816
MEDIUM
Admidio has Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions
CVSS 5.7
CVE-2026-32755
MEDIUM
Admidio is Missing CSRF Protection on Role Membership Date Changes
CVSS 5.7
CVE-2026-4068
MEDIUM
Add Custom Fields to Media <= 2.0.3 - Cross-Site Request Forgery to Custom Field Deletion via 'delete' Parameter
CVSS 4.3
CVE-2026-22323
HIGH
Cross‑Site Request Forgery in Link Aggregation Configuration
CVSS 7.1
CVE-2026-27978
MEDIUM
Next.js: null origin can bypass Server Actions CSRF checks
CVSS 4.3
CVE-2026-32839
MEDIUM
Edimax GS-5008PL <= 1.00.54 CSRF via Management CGI Endpoints
CVSS 4.3
CVE-2026-29521
MEDIUM
Hereta ETH-IMC408M CSRF via Configuration Setup
CVSS 4.3
CVE-2026-32456
MEDIUM
Admin Menu Editor <= 1.14.1 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities
9,302
Exploit Likelihood
Medium