CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,489 vulnerabilities with CWE-352
CVE-2026-8410
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete
CVSS 8.8
CVE-2026-8409
HIGH
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete
CVSS 8.8
CVE-2026-7882
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to CSRF via the DeleteFile controller
CVSS 4.3
CVE-2026-8428
HIGH
CSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and below
CVSS 8.8
CVE-2026-8426
HIGH
Concrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package overwrite
CVSS 8.8
CVE-2026-8421
HIGH
Concrete CMS <= 9.5.0 - Admin Cross-Site Request Forgery Code Execution
CVSS 8.8
CVE-2026-8417
HIGH
Concrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controller
CVSS 8.8
CVE-2026-8140
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controller
CVSS 6.5
CVE-2026-22880
MEDIUM
Mobile SSO authentication flow allows credential theft via malicious server
CVSS 6.1
CVE-2026-44925
HIGH
InfoScale Operations Manager 9.1.3 - Cross-Site Request Forgery
CVSS 8.8
CVE-2026-6405
MEDIUM
Anomify AI <= 0.3.6 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-8424
MEDIUM
Remove Yellow BGBOX <= 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-8423
MEDIUM
JaviBola Custom Theme Test <= 2.0.5 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-8420
MEDIUM
BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update
CVSS 6.1
CVE-2026-8419
MEDIUM
Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update
CVSS 4.3
CVE-2026-8418
MEDIUM
Games Catalog <= 1.2.0 - Cross-Site Request Forgery to Arbitrary Game/Post Deletion
CVSS 4.3
CVE-2026-6452
MEDIUM
Bigfishgames Syndicate <= 1.2 - Cross-Site Request Forgery to Settings Reset and Update
CVSS 4.3
CVE-2026-6401
MEDIUM
Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-6400
MEDIUM
Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Settings Update via Plugin Settings Form
CVSS 4.3
CVE-2026-6395
MEDIUM
Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripting via Settings Page
CVSS 6.1
CVE-2026-6391
MEDIUM
Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Page Parameters
CVSS 6.1
CVE-2026-8604
HIGH
Cross-Site request forgery (CSRF) in ScadaBR
CVSS 8.8
CVE-2026-45317
MEDIUM
Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation
CVSS 4.6
CVE-2026-45773
MEDIUM
Turborepo: Login callback CSRF/session fixation
CVSS 6.5
CVE-2026-8425
MEDIUM
Notify Odoo <= 1.0.1 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
Details
Vulnerabilities
9,489
Exploit Likelihood
Medium