CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,489 vulnerabilities with CWE-352
CVE-2026-39618 MEDIUM
WordPress NewsExo theme <= 7.1 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 4.3
CVE-2026-39617 CRITICAL
WordPress Bluestreet theme <= 1.7.3 - Cross Site Request Forgery (CSRF) to Arbitrary Plugin Installation vulnerability
CVSS 9.6
CVE-2026-39603 MEDIUM
WordPress Grand Photography theme <= 5.7.8 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 5.4
CVE-2026-4141 MEDIUM
Quran Translations <= 1.7 - Cross-Site Request Forgery to Playlist Settings Form
CVSS 4.3
CVE-2026-3499 HIGH
Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions
CVSS 8.8
CVE-2026-4401 MEDIUM
Download Monitor <= 5.1.10 - Cross-Site Request Forgery to Download Path Deletion and Disabling
CVSS 5.4
CVE-2026-39371 HIGH
RedwoodSDK <1.0.6 Server Function Dispatch - Cross-Site Request Forgery
CVSS 8.1
CVE-2026-34904 HIGH
WordPress Simple Social Media Share Buttons plugin <= 6.2.0 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 7.5
CVE-2026-34896 HIGH
WordPress Under Construction, Coming Soon & Maintenance Mode plugin <= 2.1.1 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 7.5
CVE-2026-35181 MEDIUM
WWBN AVideo Affected by CSRF on Player Skin Configuration via admin/playerUpdate.json.php
CVSS 4.3
CVE-2026-35180 MEDIUM
WWBN AVideo affected by CSRF on Site Customization Endpoint Enables Logo Overwrite via Base64 File Write
CVSS 4.3
CVE-2026-5624 MEDIUM
ProjectSend upload.php cross-site request forgery
CVSS 4.3
CVE-2026-5572 MEDIUM
Technostrobe HI-LED-WR120-G2 cross-site request forgery
CVSS 4.3
CVE-2026-34228 MEDIUM
Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write
CVSS 6.5
CVE-2026-34749 MEDIUM
Payload <3.79.1 Authentication Flow - CSRF Protection Bypass
CVSS 5.4
CVE-2026-5283 MEDIUM
Google Chrome <146.0.7680.178 - Info Disclosure
CVSS 6.5
CVE-2026-34613 MEDIUM
AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins
CVSS 6.5
CVE-2026-34611 MEDIUM
AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users
CVSS 6.5
CVE-2026-34394 HIGH
AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking
CVSS 8.1
CVE-2026-34384 MEDIUM
Admidio: Missing CSRF Protection on Registration Approval Actions
CVSS 4.5
CVE-2026-34383 MEDIUM
Admidio: CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter
CVSS 4.3
CVE-2026-34382 MEDIUM
Admidio: Missing CSRF Protection on Custom List Deletion in mylist_function.php
CVSS 4.6
CVE-2026-3191 MEDIUM
Minify HTML <= 2.1.12 - Cross-Site Request Forgery to Plugin Settings Update
CVSS 5.4
CVE-2026-33373 HIGH
Zimbra Collaboration 10.0-10.1 - CSRF
CVSS 8.8
CVE-2026-4315 HIGH
WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI
Details
Vulnerabilities 9,489
Exploit Likelihood Medium