CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
8,872 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 175 of 178
- CVE-2026-49396HIGHCVSS 7.1EG 7.12026-06-10
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.0.14, cross-site GET request can trigger stored cron commands on a victim's agents. This issue has been …
- CVE-2026-49433MEDIUMCVSS 5.0EG 5.02026-06-01
The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address an…
- CVE-2026-49471HIGHCVSS 8.3EG 8.32026-07-07
Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port, with no authenticati…
- CVE-2026-4968MEDIUMCVSS 4.3EG 4.32026-03-27
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The attack may be launched remotely. The ex…
- CVE-2026-4971MEDIUMCVSS 4.3EG 4.32026-03-27
A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been made…
- CVE-2026-49871CRITICALCVSS 9.3EG 9.32026-06-19
Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to bec…
- CVE-2026-50132HIGHCVSS 7.3EG 7.32026-06-22
Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, state-changing operation: it binds an external chat identity (…
- CVE-2026-50743MEDIUMCVSS 5.4EG 5.42026-07-20
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allo…
- CVE-2026-52100HIGHCVSS 7.5EG 7.52026-07-14
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function
- CVE-2026-52784HIGHCVSS 8.8EG 8.82026-06-26
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST parameter "user[admin]". This vulnerability is fixed in 17.3.3 and 17.4.1.
- CVE-2026-52800HIGHCVSS 8.8EG 8.82026-06-23
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF protection. If a victim who is an organization owner is logged in and is tricked into visit…
- CVE-2026-5283MEDIUMCVSS 6.5EG 6.52026-04-01
Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-5365MEDIUMCVSS 4.3EG 4.32026-05-14
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2. This is due to missing nonce verification on the request_cancellation() function. This makes it possible for unauthen…
- CVE-2026-53663LOWCVSS 3.1EG 3.12026-06-15
React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerab…
- CVE-2026-53736MEDIUMCVSS 4.3EG 4.32026-06-10
Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates…
- CVE-2026-53739MEDIUMCVSS 4.3EG 4.32026-06-10
Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request tha…
- CVE-2026-53760MEDIUMCVSS 5.2EG 5.22026-07-09
Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests ## Summary The `modules/plugins.php` endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token vali…
- CVE-2026-54220HIGHCVSS 8.6EG 8.62026-06-18
uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions. Because vendor contact attempts were unsuc…
- CVE-2026-54359HIGHCVSS 7.1EG 7.12026-06-12
MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on t…
- CVE-2026-5572MEDIUMCVSS 4.3EG 4.32026-04-05
A security flaw has been discovered in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has b…
- CVE-2026-55741HIGHCVSS 8.8EG 8.82026-06-18
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data via …
- CVE-2026-55742CRITICALCVSS 9.6EG 9.62026-06-18
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (includin…
- CVE-2026-55744HIGHCVSS 8.1EG 8.12026-06-18
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.main.php, the file upload action ('a=upload') processes uploaded files without cal…
- CVE-2026-55745MEDIUMCVSS 5.4EG 5.42026-06-18
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (tit…
- CVE-2026-56024MEDIUMCVSS 6.5EG 6.52026-06-18
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0.
- CVE-2026-5624MEDIUMCVSS 4.3EG 4.32026-04-06
A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit ha…
- CVE-2026-57283MEDIUMCVSS 4.3EG 4.32026-06-24
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline…
- CVE-2026-57290MEDIUMCVSS 4.3EG 4.32026-06-24
A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite the global job priority configuration.
- CVE-2026-57292MEDIUMCVSS 5.4EG 5.42026-06-24
A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.
- CVE-2026-57295MEDIUMCVSS 5.4EG 5.42026-06-24
A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another m…
- CVE-2026-57298MEDIUMCVSS 5.4EG 5.42026-06-24
A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to have Jenkins connect to an attacker-specified URL using an attacker-specified username, API k…
- CVE-2026-57305MEDIUMCVSS 5.4EG 5.42026-06-24
A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified username and password.
- CVE-2026-57306MEDIUMCVSS 4.2EG 4.22026-06-24
A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through anothe…
- CVE-2026-57635MEDIUMCVSS 6.5EG 6.52026-06-26
Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.
- CVE-2026-57637MEDIUMCVSS 4.3EG 4.32026-06-26
Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
- CVE-2026-57641MEDIUMCVSS 6.5EG 6.52026-06-26
Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.
- CVE-2026-57655HIGHCVSS 8.2EG 8.22026-06-26
Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.
- CVE-2026-57657MEDIUMCVSS 4.3EG 4.32026-06-26
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.
- CVE-2026-57659HIGHCVSS 8.8EG 8.82026-06-26
Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.
- CVE-2026-57690MEDIUMCVSS 4.3EG 4.32026-07-02
Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.
- CVE-2026-57723HIGHCVSS 7.4EG 7.42026-07-01
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.
- CVE-2026-57747MEDIUMCVSS 6.5EG 6.52026-07-02
Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
- CVE-2026-57751HIGHCVSS 8.1EG 8.12026-07-02
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
- CVE-2026-57757HIGHCVSS 7.1EG 7.12026-07-02
Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
- CVE-2026-57758HIGHCVSS 7.1EG 7.12026-07-02
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
- CVE-2026-57759HIGHCVSS 8.8EG 8.82026-07-02
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
- CVE-2026-57761HIGHCVSS 7.1EG 7.12026-07-02
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
- CVE-2026-57766HIGHCVSS 8.8EG 8.82026-07-02
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
- CVE-2026-57786HIGHCVSS 8.8EG 8.82026-07-13
Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.
- CVE-2026-5791MEDIUMCVSS 6.5EG 9.62026-05-07
Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →