CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,489 vulnerabilities with CWE-352
CVE-2026-4971 MEDIUM
SourceCodester Note Taking App cross-site request forgery
CVSS 4.3
CVE-2026-4968 MEDIUM
SourceCodester Diary App diary.php cross-site request forgery
CVSS 4.3
CVE-2026-4984 HIGH
Botpress - Credential Disclosure via Twilio Webhook Handler
CVSS 8.2
CVE-2026-4393 MEDIUM
Automated Logout - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-030
CVSS 4.3
CVE-2026-1032 MEDIUM
Conditional Menus <= 1.2.6 - Cross-Site Request Forgery to Menu Options Update
CVSS 4.3
CVE-2026-3857 HIGH
Cross-Site Request Forgery (CSRF) in GitLab
CVSS 8.1
CVE-2026-27659 MEDIUM
Mattermost <= 11.4.0 - Access Control Policy Activation CSRF
CVSS 4.6
CVE-2026-3211 MEDIUM
Theme Negotiation by Rules - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-012
CVSS 4.3
CVE-2026-29839 HIGH
DedeCMS v5.7.118 - Cross-Site Request Forgery in sys_task_add.php
CVSS 8.8
CVE-2026-33252 HIGH
MCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without Authorizatrion
CVSS 7.1
CVE-2026-33649 HIGH
AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification
CVSS 8.1
CVE-2026-33507 HIGH
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
CVSS 8.8
CVE-2026-4590 LOW
kalcaddle kodbox loginSubmit API index.class.php cross-site request forgery
CVSS 3.1
CVE-2026-31849 MEDIUM
Missing CSRF protection on state-changing endpoints in Nexxt Nebula 300+
CVSS 6.5
CVE-2026-4143 MEDIUM
Neos Connector for Fakturama <= 0.0.14 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-3332 MEDIUM
Xhanch - My Advanced Settings <= 1.1.2 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-3331 MEDIUM
Lobot Slider Administrator <= 0.6.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-2723 MEDIUM
Post Snippits <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update
CVSS 6.1
CVE-2026-1503 MEDIUM
login_register <= 1.2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVSS 4.3
CVE-2026-1393 MEDIUM
Add Google Social Profiles to Knowledge Graph Box <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1392 MEDIUM
SR WP Minify HTML <= 2.1 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1390 MEDIUM
Redirect countdown <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1378 MEDIUM
WP Posts Re-order <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-32989 HIGH
Precurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file upload
CVSS 8.8
CVE-2026-33372 MEDIUM
Zimbra Collaboration 10.0-10.1 - CSRF
CVSS 5.4
Details
Vulnerabilities 9,489
Exploit Likelihood Medium