CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,489 vulnerabilities with CWE-352
CVE-2026-57785 HIGH
WordPress ApusListing theme <= 1.2.63 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 8.8
CVE-2026-57784 CRITICAL
WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 9.6
CVE-2026-57626 HIGH
WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 7.1
CVE-2026-24537 MEDIUM
WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 4.3
CVE-2026-65757 HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension
CVSS 8.1
CVE-2026-64876 HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension
CVSS 8.8
CVE-2026-64871 MEDIUM
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension
CVSS 5.4
CVE-2026-64791 HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager
CVSS 8.8
CVE-2026-63684 HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension
CVSS 8.8
CVE-2026-63280 HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager
CVSS 8.8
CVE-2026-63265 HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints
CVSS 8.0
CVE-2026-62563 MEDIUM
Oracle Work IN Process < 12.2.15 - Improper Authorization
CVSS 5.4
CVE-2026-62487 MEDIUM
Oracle Contracts Integration < 12.2.15 - Cross-Site Request Forgery (CSRF)
CVSS 6.1
CVE-2026-62443 HIGH
Oracle Contracts Integration < 12.2.15 - Denial of Service
CVSS 7.1
CVE-2026-61253 MEDIUM
Oracle Hrms (Japanese) < 12.2.15 - Cross-Site Request Forgery (CSRF)
CVSS 5.4
CVE-2026-61217 MEDIUM
Oracle Security Service - Improper Access Control
CVSS 6.4
CVE-2026-61204 CRITICAL
PeopleSoft Enterprise FIN Program Mgmt 9.2 Auth RCE via Primavera Integration
CVSS 9.0
CVE-2026-61132 HIGH
Oracle Commerce 11.4.0 - CSRF with Data Access/Modification via Dynamo Framework
CVSS 7.6
CVE-2026-61101 HIGH
Oracle MES for Process Manufacturing 12.2.3-12.2.15: Unauthenticated Data Access/Mod via HTTP w/ User Interaction
CVSS 8.2
CVE-2026-61097 CRITICAL
Oracle Banking Trade Finance Process Management < 14.8.0 - Denial of Service
CVSS 9.6
CVE-2026-61082 MEDIUM
MySQL Connectors 9.7.0-9.7.1 - Unauthenticated Unauthorized Data Access via Connector/J
CVSS 6.5
CVE-2026-60962 MEDIUM
Oracle Flow Manufacturing 12.2.3-12.2.15 - Cross-Site Request Forgery and Unauthorized Data Access via HTTP
CVSS 5.4
CVE-2026-60957 MEDIUM
Oracle Transportation Execution 12.2.3-12.2.15 - Cross-Site Request Forgery via HTTP with Scope Change Impact
CVSS 5.4
CVE-2026-60911 MEDIUM
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60886 HIGH
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP with User Interaction
CVSS 7.6
Details
Vulnerabilities 9,489
Exploit Likelihood Medium