CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,489 vulnerabilities with CWE-352
CVE-2026-6396
MEDIUM
Fast & Fancy Filter – 3F <= 1.2.2 - Cross-Site Request Forgery to Settings Modification via fff_save_settins AJAX Action
CVSS 4.3
CVE-2026-6294
MEDIUM
Google PageRank Display <= 1.4 - Cross-Site Request Forgery to Settings Update via Settings Page
CVSS 4.3
CVE-2026-4140
MEDIUM
Ni WooCommerce Order Export <= 3.1.6 - Cross-Site Request Forgery to Settings Update via ni_order_export_action AJAX Action
CVSS 4.3
CVE-2026-4139
MEDIUM
mCatFilter <= 0.5.2 - Cross-Site Request Forgery via compute_post() Function
CVSS 4.3
CVE-2026-4138
MEDIUM
DX Unanswered Comments <= 1.7 - Cross-Site Request Forgery via Settings Update
CVSS 4.3
CVE-2026-4133
MEDIUM
TextP2P Texting Widget <= 1.7 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-4131
MEDIUM
WP Responsive Popup + Optin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'wpo_image_url' Parameter
CVSS 6.1
CVE-2026-4121
MEDIUM
Kcaptcha <= 1.0.1 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-4118
MEDIUM
Call To Action Plugin <= 3.1.3 - Cross-Site Request Forgery via Settings Update
CVSS 4.3
CVE-2026-4090
MEDIUM
Inquiry cart <= 3.4.2 - Cross-Site Request Forgery via Settings Form
CVSS 6.1
CVE-2026-40929
MEDIUM
WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators
CVSS 5.4
CVE-2026-40928
MEDIUM
AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion
CVSS 5.4
CVE-2026-40926
HIGH
WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script)
CVSS 7.1
CVE-2026-40925
HIGH
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
CVSS 8.3
CVE-2026-40883
HIGH
goshs: CSRF in state-changing GET routes enables authenticated file deletion and directory creation
CVSS 8.1
CVE-2026-41194
MEDIUM
FreeScout's Mailbox OAuth disconnect uses a state-changing GET and is CSRFable
CVSS 5.4
CVE-2026-31014
MEDIUM
Dovestones Softwares AD Self Update <4.0.0.5 - CSRF
CVSS 6.3
CVE-2026-6777
MEDIUM
Mozilla Firefox and Thunderbird 150 - DNS Component Input Validation Issue
CVSS 5.3
CVE-2026-6755
MEDIUM
Mitigation bypass in the DOM: postMessage component
CVSS 6.5
CVE-2026-6589
MEDIUM
ComfyUI server.py create_origin_only_middleware cross-site request forgery
CVSS 4.3
CVE-2026-40948
MEDIUM
Apache Airflow: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager
CVSS 5.4
CVE-2026-40581
HIGH
ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion
CVSS 8.1
CVE-2026-40458
MEDIUM
Cross-Site Request Forgery in PAC4J
CVSS 6.5
CVE-2026-6451
MEDIUM
CMS für Motorrad Werkstätten <= 1.0.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-1852
MEDIUM
Product Pricing Table by WooBeWoo <= 1.1.0 - Cross-Site Request Forgery to Stored XSS and Pricing Table Deletion
CVSS 6.1
Details
Vulnerabilities
9,489
Exploit Likelihood
Medium