CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,489 vulnerabilities with CWE-352
CVE-2026-12986
HIGH
Payara Server - Cross-Site Request Forgery (CSRF)
CVE-2026-57306
MEDIUM
Jenkins Zowe zDevOps Plugin - Cross-Site Request Forgery (CSRF)
CVSS 4.2
CVE-2026-57305
MEDIUM
Jenkins Assembla Plugin < 1.4 - Cross-Site Request Forgery (CSRF)
CVSS 5.4
CVE-2026-57298
MEDIUM
Jenkins Contrast Continuous Application Security Plugin < 3.11 - Cross-Site Request Forgery (CSRF)
CVSS 5.4
CVE-2026-57295
MEDIUM
Jenkins EC2 Fleet Plugin - Cross-Site Request Forgery (CSRF)
CVSS 5.4
CVE-2026-57292
MEDIUM
Jenkins Gitee Plugin - Cross-Site Request Forgery (CSRF)
CVSS 5.4
CVE-2026-57290
MEDIUM
Jenkins Priority Sorter Plugin < 936.v2c01c6b_84449 - Cross-Site Request Forgery (CSRF)
CVSS 4.3
CVE-2026-57283
MEDIUM
Jenkins Pipeline: Groovy Plugin < 4331.v9d06ed4658ff - Cross-Site Request Forgery (CSRF)
CVSS 4.3
CVE-2026-9724
MEDIUM
MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-9721
MEDIUM
Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-8905
MEDIUM
Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameter
CVSS 6.1
CVE-2026-6292
MEDIUM
MP Customize Login Page <= 1.0 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-11997
MEDIUM
Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update
CVSS 4.3
CVE-2026-10552
MEDIUM
Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter
CVSS 4.3
CVE-2026-53663
LOW
React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass
CVSS 3.1
CVE-2026-49871
CRITICAL
Apache APISIX: cas-auth login CSRF / session injection issue
CVSS 9.3
CVE-2026-11775
MEDIUM
User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-56024
MEDIUM
WordPress WP EasyPay plugin <= 4.4.0 - Cross Site Request Forgery (CSRF) vulnerability
CVSS 6.5
CVE-2026-54220
HIGH
Cross-Site Request Forgery in UBB.threads
CVE-2026-55745
MEDIUM
Cotonti CSRF in PFS folder edit allows unauthorized folder modification
CVSS 5.4
CVE-2026-55744
HIGH
Cotonti CSRF in PFS allows forced arbitrary file upload
CVSS 8.1
CVE-2026-55742
CRITICAL
Cotonti CSRF in admin.rights.php allows privilege escalation
CVSS 9.6
CVE-2026-55741
HIGH
Cotonti CSRF in admin.config.php allows unauthorized configuration changes
CVSS 8.8
CVE-2026-11784
MEDIUM
Optimole < 4.2.6 - CSRF
CVSS 4.3
CVE-2026-9591
MEDIUM
Cross-Site Request Forgery (CSRF) in SimplCommerce News Module
Details
Vulnerabilities
9,489
Exploit Likelihood
Medium