CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,489 vulnerabilities with CWE-352
CVE-2026-35220
MEDIUM
Joomla! Core - [20260505] - CSRF in user activation endpoint
CVSS 4.3
CVE-2026-46620
MEDIUM
e107: CSRF in comment.php moderation endpoints via token-optional validation in session_handler::check()
CVSS 6.5
CVE-2026-8174
MEDIUM
Zohocorp Zoho Mail wordpress plugin - Cross-Site Request Forgery
CVSS 5.7
CVE-2026-39436
HIGH
WordPress CformsII plugin <= 15.1.3 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 7.1
CVE-2026-24554
MEDIUM
WordPress WPSubscription plugin <= 1.9.1 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 4.3
CVE-2026-24597
MEDIUM
WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 4.3
CVE-2026-24574
MEDIUM
WordPress Export WP Page to Static HTML/CSS plugin <= 6.0.0 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 6.5
CVE-2026-9486
MEDIUM
SourceCodester Student Grades Management System cross-site request forgery
CVSS 4.3
CVE-2026-9303
MEDIUM
calcom cal.diy cross-site request forgery
CVSS 4.3
CVE-2026-41074
HIGH
bestpractical - RT Has Broken CSRF Protection for Authenticated Users
CVSS 7.1
CVE-2026-40864
MEDIUM
JupyterHub: Cross-origin form POSTs bypass XSRF
CVSS 5.4
CVE-2026-8340
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion
CVSS 4.3
CVE-2026-7615
MEDIUM
Widget Context <= 1.3.3 - Cross-Site Request Forgery to Settings Update via 'wl' Parameter
CVSS 4.3
CVE-2026-4070
MEDIUM
Alfie <= 1.2.1 - Cross-Site Request Forgery to Feed Deletion via 'delete' Parameter
CVSS 4.3
CVE-2026-8435
MEDIUM
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()
CVSS 6.5
CVE-2026-8434
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()
CVSS 8.8
CVE-2026-8433
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()
CVSS 8.8
CVE-2026-8432
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()
CVSS 8.8
CVE-2026-8427
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)
CVSS 8.8
CVE-2026-8416
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)
CVSS 8.8
CVE-2026-8415
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder
CVSS 8.8
CVE-2026-8414
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate
CVSS 8.8
CVE-2026-8413
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design
CVSS 8.8
CVE-2026-8412
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache
CVSS 8.8
CVE-2026-8411
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete
CVSS 8.8
Details
Vulnerabilities
9,489
Exploit Likelihood
Medium