CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,302 vulnerabilities with CWE-352
CVE-2026-11148 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Payments Implementation
CVSS 6.5
CVE-2026-11139 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Paint Implementation
CVSS 6.5
CVE-2026-11134 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Media Component
CVSS 6.5
CVE-2026-11129 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Extensions
CVSS 6.5
CVE-2026-11106 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Media Component
CVSS 6.5
CVE-2026-11084 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Password Manager
CVSS 6.5
CVE-2026-11083 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Password Manager
CVSS 6.5
CVE-2026-11020 MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via Crafted XML File
CVSS 6.5
CVE-2026-43985 HIGH
Tautulli < 2.17.1 - CSRF Admin Credential Takeover
CVSS 8.8
CVE-2026-9732 MEDIUM
EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update
CVSS 4.3
CVE-2026-42073 MEDIUM
OpenClaude's MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
CVSS 6.5
CVE-2026-34460 MEDIUM
NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swapping
CVSS 5.4
CVE-2026-9730 MEDIUM
Remove NoFollow Commenter URL <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-9723 MEDIUM
Google Plus One Bottom <= 0.0.2 - Cross-Site Request Forgery to Plugin Settings Update via Settings Page
CVSS 4.3
CVE-2026-9722 MEDIUM
Laiser Tag <= 1.2.5 - Cross-Site Request Forgery to Plugin Settings Update via Settings Form
CVSS 4.3
CVE-2026-9599 MEDIUM
Tectite Forms <= 1.3 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-8422 MEDIUM
Remove meta boxes per user role <= 1.01 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-4071 MEDIUM
BirdSeed <= 2.2.0 - Cross-Site Request Forgery via BirdSeed Token Change
CVSS 4.3
CVE-2026-49433 MEDIUM
DeepAI - Cross-Site Request Forgery via Email Change Endpoint
CVSS 5.0
CVE-2026-40549 MEDIUM
Cross-Site Request Forgery in SOPlanning
CVE-2026-45610 MEDIUM
WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA
CVSS 5.7
CVE-2026-6075 HIGH
Media Library Assistant <= 3.35 - Cross-Site Request Forgery via Bulk Action Form
CVSS 8.1
CVE-2026-35266 HIGH
Oracle Rest Data Services < 26.1.0 - Denial of Service
CVSS 7.9
CVE-2026-9618 MEDIUM
PeachPay <= 1.120.46 - Cross-Site Request Forgery to Stripe Unlink
CVSS 4.3
CVE-2026-6455 HIGH
WP Contact Form 7 DB Handler <= 3.0 - Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter
CVSS 8.1
Details
Vulnerabilities 9,302
Exploit Likelihood Medium