CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,302 vulnerabilities with CWE-352
CVE-2026-8140
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to CSRF on download() in the package install controller
CVSS 6.5
CVE-2026-22880
MEDIUM
Mobile SSO authentication flow allows credential theft via malicious server
CVSS 6.1
CVE-2026-44925
HIGH
InfoScale Operations Manager 9.1.3 - Cross-Site Request Forgery
CVSS 8.8
CVE-2026-6405
MEDIUM
Anomify AI <= 0.3.6 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-8424
MEDIUM
Remove Yellow BGBOX <= 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-8423
MEDIUM
JaviBola Custom Theme Test <= 2.0.5 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-8420
MEDIUM
BLOGCHAT Chat System <= 1.3.6.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update
CVSS 6.1
CVE-2026-8419
MEDIUM
Amazon Scraper <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update
CVSS 4.3
CVE-2026-8418
MEDIUM
Games Catalog <= 1.2.0 - Cross-Site Request Forgery to Arbitrary Game/Post Deletion
CVSS 4.3
CVE-2026-6452
MEDIUM
Bigfishgames Syndicate <= 1.2 - Cross-Site Request Forgery to Settings Reset and Update
CVSS 4.3
CVE-2026-6401
MEDIUM
Bottom Bar <= 0.1.7 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-6400
MEDIUM
Child Height Predictor by Ostheimer <= 1.3 - Cross-Site Request Forgery to Settings Update via Plugin Settings Form
CVSS 4.3
CVE-2026-6395
MEDIUM
Word 2 Cash <= 0.9.2 - Cross-Site Request Forgeryto Stored Cross-Site Scripting via Settings Page
CVSS 6.1
CVE-2026-6391
MEDIUM
Sentence To SEO (keywords, description and tags) <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Page Parameters
CVSS 6.1
CVE-2026-8604
HIGH
Cross-Site request forgery (CSRF) in ScadaBR
CVSS 8.8
CVE-2026-45317
MEDIUM
Open WebUI: Cross-Site Request Forgery (CSRF) via Image URL Manipulation
CVSS 4.6
CVE-2026-45773
MEDIUM
Turborepo: Login callback CSRF/session fixation
CVSS 6.5
CVE-2026-8425
MEDIUM
Notify Odoo <= 1.0.1 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-28761
HIGH
Fujitsu Japan Limited Musetheque V4 Information Disclosure For Ipknowledge - Cross-Site Request Forgery (CSRF)
CVSS 8.1
CVE-2026-5365
MEDIUM
LatePoint <= 5.3.2 - Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route
CVSS 4.3
CVE-2026-4527
MEDIUM
Cross-Site Request Forgery (CSRF) in GitLab
CVSS 6.5
CVE-2026-44364
CRITICAL
misp-modules website - Missing CSRF protection in the website home blueprint
CVE-2026-41255
MEDIUM
CKAN: CSRF exemption primed by anonymous requests
CVSS 6.1
CVE-2026-40703
MEDIUM
BIG-IP 16.1.0-17.1.3.1 17.5.0-17.5.1.4 >=21.0.0 - Cross-Site Request Forgery in Dashboard
CVSS 5.4
CVE-2026-44548
HIGH
ChurchCRM: CSRF via legacy GET-delete pages (FundRaiserDelete.php, PropertyTypeDelete.php, NoteDelete.php)
CVSS 8.1
Details
Vulnerabilities
9,302
Exploit Likelihood
Medium