CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
8,872 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 176 of 178
- CVE-2026-58143HIGHCVSS 8.8EG 8.82026-07-09
Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into submitting a forged POST request to…
- CVE-2026-58315MEDIUMCVSS 4.3EG 4.32026-07-07
Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged into Web Config, unintended operations may be performed.
- CVE-2026-58476HIGHCVSS 8.1EG 8.12026-07-14
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visitin…
- CVE-2026-58482MEDIUMCVSS 5.9EG 5.92026-07-20
Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate`…
- CVE-2026-58489MEDIUMCVSS 6.8EG 6.82026-07-13
HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2 state value but only checked that it was present rather than validating it against the value…
- CVE-2026-58518MEDIUMCVSS 6.3EG 6.32026-07-01
Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3.
- CVE-2026-59148HIGHCVSS 8.8EG 8.82026-07-09
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtime…
- CVE-2026-5918MEDIUMCVSS 4.3EG 4.32026-04-08
Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-5923MEDIUMCVSS 6.0EG 6.02026-07-08
Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.
- CVE-2026-59520MEDIUMCVSS 4.3EG 4.32026-07-05
Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.
- CVE-2026-59713HIGHCVSS 8.1EG 8.12026-07-06
Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes …
- CVE-2026-60025HIGHCVSS 8.8EG 8.82026-07-17
The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
- CVE-2026-6075HIGHCVSS 8.1EG 8.12026-05-29
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This ma…
- CVE-2026-6109MEDIUMCVSS 4.3EG 4.32026-04-12
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manip…
- CVE-2026-61204CRITICALCVSS 9.0EG 9.02026-07-21
Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-61217MEDIUMCVSS 6.4EG 6.42026-07-21
Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with ne…
- CVE-2026-61253MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker…
- CVE-2026-61502MEDIUMCVSS 4.3EG 4.32026-07-13
Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configurat…
- CVE-2026-61956HIGHCVSS 7.1EG 7.12026-07-13
Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی …
- CVE-2026-62236MEDIUMCVSS 5.4EG 5.42026-07-17
grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti…
- CVE-2026-62443HIGHCVSS 7.1EG 7.12026-07-21
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2026-62487MEDIUMCVSS 6.1EG 6.12026-07-21
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2026-62563MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-6292MEDIUMCVSS 4.3EG 4.32026-06-24
The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely broken nonce validation in the enter_mpclp_login_options() function, w…
- CVE-2026-6293MEDIUMCVSS 4.3EG 4.32026-04-15
The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combi…
- CVE-2026-6294MEDIUMCVSS 4.3EG 4.32026-04-22
The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay_option() function, which handles the plugin settings…
- CVE-2026-63265NONECVSS 0.0EG 0.02026-07-22
Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke l…
- CVE-2026-63280NONECVSS 0.0EG 0.02026-07-22
Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
- CVE-2026-63684NONECVSS 0.0EG 0.02026-07-22
Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and ite…
- CVE-2026-6391MEDIUMCVSS 6.1EG 6.12026-05-20
The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the create_admin_page(…
- CVE-2026-6395MEDIUMCVSS 6.1EG 6.12026-05-20
The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of nonce verification on the settings save h…
- CVE-2026-6396MEDIUMCVSS 4.3EG 4.32026-04-22
The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce verification in the saveFields() function, which handles the fff_save_setti…
- CVE-2026-6400MEDIUMCVSS 4.3EG 4.32026-05-20
The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the options() function, which handles plugin set…
- CVE-2026-6401MEDIUMCVSS 4.3EG 4.32026-05-20
The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing nonce verification on the plugin's settings update forms handled in bottom-bar-admin.php. Non…
- CVE-2026-6405MEDIUMCVSS 4.3EG 4.32026-05-20
The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in versions up to and including 0.3.6. This is due to missing nonce veri…
- CVE-2026-6440MEDIUMCVSS 4.3EG 4.32026-07-10
The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the res…
- CVE-2026-6451MEDIUMCVSS 4.3EG 4.32026-04-17
The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation on all eight AJAX deletion handlers: vehicles_cfmw_d_vehicle…
- CVE-2026-6452MEDIUMCVSS 4.3EG 4.32026-05-20
The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the bigfishgames_syndicate_submenu() function. T…
- CVE-2026-6455HIGHCVSS 8.1EG 8.12026-05-28
The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing n…
- CVE-2026-64791NONECVSS 0.0EG 0.02026-07-22
Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.
- CVE-2026-64821MEDIUMCVSS 4.3EG 4.32026-07-21
djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users by exploiting order-cancellation logic i…
- CVE-2026-6589MEDIUMCVSS 4.3EG 4.32026-04-20
A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. …
- CVE-2026-6700MEDIUMCVSS 4.3EG 4.32026-05-05
The DX Sources plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation on the settings_page_build function. This makes it possible f…
- CVE-2026-6701MEDIUMCVSS 4.3EG 4.32026-05-05
The addfreespace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated a…
- CVE-2026-6702MEDIUMCVSS 6.1EG 6.12026-05-05
The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the '/wp-admin/options-general.php?page=admin.php' pa…
- CVE-2026-6710MEDIUMCVSS 4.3EG 4.32026-05-12
The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the SkysaApps_Admin_AppPage function. This makes …
- CVE-2026-6755MEDIUMCVSS 6.5EG 6.52026-04-21
Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
- CVE-2026-6777MEDIUMCVSS 5.3EG 5.32026-04-21
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
- CVE-2026-6932MEDIUMCVSS 4.3EG 4.32026-05-12
The Woo Commerce Minimum Weight plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.0.1. This is due to missing nonce verification on the settings update handler in edit-weight.php. This m…
- CVE-2026-7047MEDIUMCVSS 4.3EG 4.32026-06-05
The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_ajax_modify_notes function. This makes i…
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →