CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,489 vulnerabilities with CWE-352
CVE-2026-60842 MEDIUM
Oracle Knowledge Mgmt 12.2.5-12.2.15: Unauth CSRF & Data Disclosure via HTTP Search
CVSS 6.1
CVE-2026-60685 MEDIUM
Oracle iSupport 12.2.3-12.2.15 - Unauthenticated Cross-Site Request Forgery via HTTP with Impact to Additional Products
CVSS 6.1
CVE-2026-60664 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60658 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 7.5
CVE-2026-60650 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60648 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60646 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Web Content Management
CVSS 8.0
CVE-2026-60643 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Code Execution via Content Server
CVSS 8.0
CVE-2026-60642 HIGH
Oracle WebCenter Content - Denial of Service
CVSS 7.6
CVE-2026-60640 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.3
CVE-2026-60639 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60638 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60637 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60636 HIGH
Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 - Unauthenticated Remote Code Execution via Content Server
CVSS 8.8
CVE-2026-60635 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60634 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP with User Interaction
CVSS 8.8
CVE-2026-60633 HIGH
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.8
CVE-2026-60631 CRITICAL
Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Arbitrary Data Creation, Deletion, and Access via HTTP
CVSS 9.3
CVE-2026-47000 LOW
Oracle Enterprise Manager Base Platform 24.1 - Authenticated Data Modification via Security Framework
CVSS 3.5
CVE-2026-64821 MEDIUM
djangoSIGE 1.10 CSRF via GET-based Order Cancellation Views
CVSS 4.3
CVE-2026-58482 MEDIUM
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
CVSS 5.9
CVE-2026-50743 MEDIUM
Revive Adserver < 6.0.7 - Cross-Site Request Forgery (CSRF)
CVSS 5.4
CVE-2026-32823 MEDIUM
dataCycle State-Changing GET Endpoints Enable CSRF
CVSS 4.3
CVE-2026-13156 MEDIUM
MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
CVSS 5.4
CVE-2026-16216 MEDIUM
geex-arts django-jet OAuth cross-site request forgery
CVSS 4.3
Details
Vulnerabilities 9,489
Exploit Likelihood Medium