CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,119 vulnerabilities with CWE-352
CVE-2026-3332 MEDIUM
Xhanch - My Advanced Settings <= 1.1.2 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-3331 MEDIUM
Lobot Slider Administrator <= 0.6.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-2723 MEDIUM
Post Snippits <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Update
CVSS 6.1
CVE-2026-1503 MEDIUM
login_register <= 1.2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVSS 4.3
CVE-2026-1393 MEDIUM
Add Google Social Profiles to Knowledge Graph Box <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1392 MEDIUM
SR WP Minify HTML <= 2.1 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1390 MEDIUM
Redirect countdown <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-1378 MEDIUM
WP Posts Re-order <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-32989 HIGH
Precurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file upload
CVSS 8.8
CVE-2026-33372 MEDIUM
Zimbra Collaboration 10.0-10.1 - CSRF
CVSS 5.4
CVE-2026-32816 MEDIUM
Admidio has Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions
CVSS 5.7
CVE-2026-32755 MEDIUM
Admidio is Missing CSRF Protection on Role Membership Date Changes
CVSS 5.7
CVE-2026-4068 MEDIUM
Add Custom Fields to Media <= 2.0.3 - Cross-Site Request Forgery to Custom Field Deletion via 'delete' Parameter
CVSS 4.3
CVE-2026-22323 HIGH
Cross‑Site Request Forgery in Link Aggregation Configuration
CVSS 7.1
CVE-2026-27978 MEDIUM
Next.js: null origin can bypass Server Actions CSRF checks
CVSS 4.3
CVE-2026-32839 MEDIUM
Edimax GS-5008PL <= 1.00.54 CSRF via Management CGI Endpoints
CVSS 4.3
CVE-2026-29521 MEDIUM
Hereta ETH-IMC408M CSRF via Configuration Setup
CVSS 4.3
CVE-2026-32456 MEDIUM
Admin Menu Editor <=1.14.1 - CSRF
CVSS 4.3
CVE-2026-32443 MEDIUM
Product Feed PRO for WooCommerce <=13.5.2 - CSRF
CVSS 6.5
CVE-2026-32420 MEDIUM
GamiPress <=7.6.6 - CSRF
CVSS 5.4
CVE-2026-32344 MEDIUM
Corpiva <=1.0.96 - CSRF
CVSS 4.3
CVE-2026-32343 MEDIUM
Magazine3 Easy Table of Contents <=2.0.80 - CSRF
CVSS 4.3
CVE-2026-32342 MEDIUM
Ays Pro Quiz Maker <=6.7.1.2 - CSRF
CVSS 4.3
CVE-2026-32330 MEDIUM
10Web Photo Gallery <=1.8.37 - CSRF
CVSS 4.3
CVE-2026-32328 MEDIUM
Lemmony <1.7.1 - CSRF
CVSS 5.4
Details
Vulnerabilities 9,119
Exploit Likelihood Medium