CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,302 vulnerabilities with CWE-352
CVE-2026-11148
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Payments Implementation
CVSS 6.5
CVE-2026-11139
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Paint Implementation
CVSS 6.5
CVE-2026-11134
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Media Component
CVSS 6.5
CVE-2026-11129
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Extensions
CVSS 6.5
CVE-2026-11106
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Media Component
CVSS 6.5
CVE-2026-11084
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Password Manager
CVSS 6.5
CVE-2026-11083
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Password Manager
CVSS 6.5
CVE-2026-11020
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Crafted XML File
CVSS 6.5
CVE-2026-43985
HIGH
Tautulli < 2.17.1 - CSRF Admin Credential Takeover
CVSS 8.8
CVE-2026-9732
MEDIUM
EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update
CVSS 4.3
CVE-2026-42073
MEDIUM
OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
CVSS 6.5
CVE-2026-34460
MEDIUM
NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping
CVSS 5.4
CVE-2026-9730
MEDIUM
Remove NoFollow Commenter URL <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-9723
MEDIUM
Google Plus One Bottom <= 0.0.2 - Cross-Site Request Forgery to Plugin Settings Update via Settings Page
CVSS 4.3
CVE-2026-9722
MEDIUM
Laiser Tag <= 1.2.5 - Cross-Site Request Forgery to Plugin Settings Update via Settings Form
CVSS 4.3
CVE-2026-9599
MEDIUM
Tectite Forms <= 1.3 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-8422
MEDIUM
Remove meta boxes per user role <= 1.01 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-4071
MEDIUM
BirdSeed <= 2.2.0 - Cross-Site Request Forgery via BirdSeed Token Change
CVSS 4.3
CVE-2026-49433
MEDIUM
DeepAI - Cross-Site Request Forgery via Email Change Endpoint
CVSS 5.0
CVE-2026-40549
MEDIUM
Cross-Site Request Forgery in SOPlanning
CVE-2026-45610
MEDIUM
WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA
CVSS 5.7
CVE-2026-6075
HIGH
Media Library Assistant <= 3.35 - Cross-Site Request Forgery via Bulk Action Form
CVSS 8.1
CVE-2026-35266
HIGH
Oracle Rest Data Services < 26.1.0 - Denial of Service
CVSS 7.9
CVE-2026-9618
MEDIUM
PeachPay <= 1.120.46 - Cross-Site Request Forgery to Stripe Unlink
CVSS 4.3
CVE-2026-6455
HIGH
WP Contact Form 7 DB Handler <= 3.0 - Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter
CVSS 8.1
Details
Vulnerabilities
9,302
Exploit Likelihood
Medium