CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,302 vulnerabilities with CWE-352
CVE-2026-44347 MEDIUM
Warpgate: SSO CSRF -- State Token Not Validated on Return
CVSS 5.8
CVE-2026-42289 HIGH
ChurchCRM: Cross-Site Request Forgery (CSRF) Leading to Admin Privilege Escalation
CVSS 8.8
CVE-2026-30807 HIGH
Pandora FMS 777-800 - Cross-Site Request Forgery
CVSS 8.8
CVE-2026-7616 MEDIUM
Zawgyi Embed <= 2.1.1 - Cross-Site Request Forgery via 'zawgyi_forceCSS' Parameter
CVSS 4.3
CVE-2026-7562 MEDIUM
WP-Redirection <= 1.0.3 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-7561 MEDIUM
Tm – WordPress Redirection <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVSS 6.1
CVE-2026-6932 MEDIUM
Woo Commerce Minimum Weight <= 3.0.1 - Cross-Site Request Forgery via Settings Update Form
CVSS 4.3
CVE-2026-6710 MEDIUM
Skysa Text Ticker App <= 1.4 - Cross-Site Request Forgery to Settings Modification via 'Save Settings' Form
CVSS 4.3
CVE-2026-45430 HIGH
Backdrop CMS Contributed Projects Backdrop-contrib/salesforce < 1.x-1.0.1 - Cross-Site Request Forgery (CSRF)
CVSS 7.1
CVE-2026-0502 MEDIUM
Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform
CVSS 5.4
CVE-2026-44695 MEDIUM
Outline: Slack OAuth state can link a victim Outline account to an attacker Slack identity
CVSS 5.8
CVE-2026-43877 MEDIUM
WWBN AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Any Logged-in User's Profile Photo with Arbitrary Bytes
CVSS 5.4
CVE-2026-38566 HIGH
HireFlow 1.2 - Cross-Site Request Forgery via Unprotected POST Endpoints
CVSS 8.1
CVE-2026-8194 MEDIUM
osTicket Dispatcher class.dispatcher.php cross-site request forgery
CVSS 4.3
CVE-2026-42286 HIGH
Emlog: Cross-Site Request Forgery in Admin Functions
CVE-2026-42190 MEDIUM
RedwoodSDK: Same-site CSRF in in server actions
CVSS 5.3
CVE-2026-5791 MEDIUM
CSRF in DivvyDrive Information Technologies' DivvyDrive
CVSS 6.5
CVE-2026-28201 HIGH
SurrealDB Injection on Open Notebook
CVSS 7.8
CVE-2026-27415 MEDIUM
WordPress BEAR plugin <= 1.1.5 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 4.3
CVE-2026-41663 LOW
Admidio: CSRF on Admin Preferences Triggers Unauthorized Backup, .htaccess Write, and Email Send
CVSS 3.5
CVE-2026-40326 HIGH
Masa CMS CSRF in site bundle creation allows unauthorized site data export
CVE-2026-40325 HIGH
Masa CMS CSRF in content restoration allows unauthorized restoration of deleted content
CVE-2026-40309 HIGH
Masa CMS CSRF in trash management allows unauthorized permanent deletion of deleted content
CVE-2026-40174 HIGH
Masa CMS CSRF in user address management allows unauthorized address changes
CVE-2026-8022 LOW
Google Chrome < 148.0.7778.96 - Cross-Origin Data Leak via MHTML
CVSS 3.1
Details
Vulnerabilities 9,302
Exploit Likelihood Medium