CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,489 vulnerabilities with CWE-352
CVE-2026-16081 MEDIUM
Sipeed PicoClaw auth.go cross-site request forgery
CVSS 4.3
CVE-2026-9734 MEDIUM
W3SC Elementor to Zoho CRM <= 2.2.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-49215 MEDIUM
Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Header is CORS-Safelisted
CVSS 5.4
CVE-2026-60025 HIGH
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0
CVSS 8.8
CVE-2026-62236 MEDIUM
grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret
CVSS 5.4
CVE-2026-35143 LOW
HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.
CVSS 3.0
CVE-2026-15005 HIGH
Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter
CVSS 8.8
CVE-2026-11866 MEDIUM
Appointment Booking Plugin < 5.6.3 - Cross-Site Request Forgery
CVSS 5.4
CVE-2026-12409 MEDIUM
Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action
CVSS 4.3
CVE-2026-26718 CRITICAL
xxl-job-admin 3.0.0 - Cross-Site Request Forgery via Glue IDE Shell Script Modification Endpoint
CVSS 9.1
CVE-2026-20296 HIGH
SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise
CVSS 8.3
CVE-2026-47158 HIGH
Vaultwarden: CSRF in SSO Authorization Flow
CVSS 8.3
CVE-2026-52100 HIGH
linx-server 1.0-2.3.8 - Cross-Site Request Forgery and Remote Code Execution via uploadPutHandler Function
CVSS 7.5
CVE-2026-15747 CRITICAL
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle
CVSS 9.1
CVE-2026-58476 HIGH
Sustainable Irrigation Platform 5.2.16 CSRF via Administrative GET Requests
CVSS 8.1
CVE-2026-58489 MEDIUM
HedgeDoc: CSRF in GitHub Gist export callback
CVE-2026-61502 MEDIUM
Rejetto HFS < 3.2.1 Cross-Site Request Forgery via GET Requests
CVSS 4.3
CVE-2026-61956 HIGH
hamsalam sync-basalam <= 1.9.1 - Cross-Site Request Forgery
CVSS 7.1
CVE-2026-57786 HIGH
WordPress WorkScout-Core plugin <= 1.7.08 - Cross Site Request Forgery (CSRF) to Broken Authentication vulnerability
CVSS 8.8
CVE-2026-15080 MEDIUM
Ray Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071
CVSS 4.3
CVE-2026-13243 MEDIUM
Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063
CVSS 4.8
CVE-2026-38057 HIGH
ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery
CVSS 8.1
CVE-2026-6440 MEDIUM
GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
CVSS 4.3
CVE-2026-15070 HIGH
Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter
CVSS 8.8
CVE-2026-44342 MEDIUM
New API CSRF in email and WeChat account binding endpoints
CVSS 5.3
Details
Vulnerabilities 9,489
Exploit Likelihood Medium