68 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2025-15399 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | CRITICAL | 10.0 | — | NVD | 2026-09-18 |
| CVE-2026-77006 | The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capa | CRITICAL | 9.6 | 8%ile | NVD | 2026-09-12 |
| CVE-2026-59160 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts it | HIGH | 8.8 | 35%ile | NVD | 2026-09-15 |
| CVE-2026-78295 | Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. | HIGH | 8.8 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-18110 | Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint | HIGH | 8.7 | 16%ile | NVD | 2026-09-15 |
| CVE-2026-81568 | Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0- | HIGH | 8.7 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-92580 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClie | HIGH | 8.7 | 64%ile | NVD | 2026-09-16 |
| CVE-2026-19535 | Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative we | HIGH | 8.6 | 16%ile | NVD | 2026-09-16 |
| CVE-2026-40857 | WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. T | HIGH | 8.4 | 9%ile | NVD | 2026-09-16 |
| CVE-2026-54507 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5 | HIGH | 8.4 | 25%ile | NVD | 2026-09-17 |
| CVE-2026-93456 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing | HIGH | 8.4 | 5%ile | NVD | 2026-09-18 |
| CVE-2026-92591 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes | HIGH | 8.2 | 15%ile | NVD | 2026-09-16 |
| CVE-2026-61593 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 8.1 | 8%ile | NVD | 2026-09-16 |
| CVE-2026-81897 | In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not vali | HIGH | 7.7 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-85385 | Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output en | HIGH | 7.7 | 36%ile | NVD | 2026-09-16 |
| CVE-2026-54087 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFie | HIGH | 7.6 | 23%ile | NVD | 2026-09-14 |
| CVE-2026-53660 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes | HIGH | 7.4 | 27%ile | NVD | 2026-09-15 |
| CVE-2026-81090 | The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the | HIGH | 7.2 | 19%ile | NVD | 2026-09-12 |
| CVE-2026-92751 | CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing | HIGH | 7.2 | 6%ile | NVD | 2026-09-16 |
| CVE-2026-92806 | phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form ha | HIGH | 7.2 | 6%ile | NVD | 2026-09-16 |
| CVE-2026-81429 | The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template | HIGH | 7.1 | 0%ile | NVD | 2026-09-12 |
| CVE-2026-81902 | Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlo | HIGH | 7.1 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-78081 | Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0 | HIGH | 7.1 | 5%ile | NVD | 2026-09-15 |
| CVE-2026-92582 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.js | HIGH | 7.1 | 2%ile | NVD | 2026-09-16 |
| CVE-2026-66571 | Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions. | HIGH | 7.1 | 1%ile | NVD | 2026-09-17 |
| CVE-2026-54510 | Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the | HIGH | 7.1 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-76856 | Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config | HIGH | 7.0 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-50025 | Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mous | MEDIUM | 6.9 | 8%ile | NVD | 2026-09-11 |
| CVE-2026-90543 | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a mis | MEDIUM | 6.9 | 28%ile | NVD | 2026-09-12 |
| CVE-2026-91819 | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-sec | MEDIUM | 6.9 | 5%ile | NVD | 2026-09-15 |
| CVE-2026-92915 | WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/use | MEDIUM | 6.9 | 24%ile | NVD | 2026-09-17 |
| CVE-2026-84023 | The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy | MEDIUM | 6.5 | 2%ile | NVD | 2026-09-12 |
| CVE-2026-85131 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk a | MEDIUM | 6.5 | 8%ile | NVD | 2026-09-16 |
| CVE-2026-49992 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request for | MEDIUM | 6.3 | 5%ile | NVD | 2026-09-11 |
| CVE-2026-81907 | Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function | MEDIUM | 6.1 | 12%ile | NVD | 2026-09-11 |
| CVE-2026-62280 | Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoin | MEDIUM | 6.1 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-81912 | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard | MEDIUM | 5.7 | 8%ile | NVD | 2026-09-11 |
| CVE-2026-62133 | Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions. | MEDIUM | 5.4 | 3%ile | NVD | 2026-09-11 |
| CVE-2026-17047 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper req | MEDIUM | 5.4 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-74005 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | MEDIUM | 5.4 | 1%ile | NVD | 2026-09-17 |
| CVE-2026-80355 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerabi | MEDIUM | 5.4 | 11%ile | NVD | 2026-09-17 |
| CVE-2026-54613 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5 | MEDIUM | 5.4 | 15%ile | NVD | 2026-09-17 |
| CVE-2026-68526 | Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concret | MEDIUM | 5.3 | 8%ile | NVD | 2026-09-11 |
| CVE-2026-91857 | Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affec | MEDIUM | 5.3 | 7%ile | NVD | 2026-09-15 |
| CVE-2026-52823 | Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id} | MEDIUM | 5.3 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-92579 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without | MEDIUM | 5.3 | 5%ile | NVD | 2026-09-16 |
| CVE-2026-54642 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored- | MEDIUM | 5.3 | 13%ile | NVD | 2026-09-17 |
| CVE-2026-82764 | Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page wh | MEDIUM | 5.1 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-90893 | MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, set | MEDIUM | 5.1 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-62139 | Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions. | MEDIUM | 4.3 | 1%ile | NVD | 2026-09-11 |
| CVE-2026-84024 | The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowin | MEDIUM | 4.3 | 1%ile | NVD | 2026-09-12 |
| CVE-2026-91009 | The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation an | MEDIUM | 4.3 | 1%ile | NVD | 2026-09-17 |
| CVE-2026-77568 | Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, a | MEDIUM | 4.2 | — | NVD | 2026-09-18 |
| CVE-2026-68532 | Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in c | LOW | 2.3 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-81919 | Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() ac | LOW | 2.3 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-81920 | Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The rese | LOW | 2.3 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-81637 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim' | LOW | 2.3 | 40%ile | NVD | 2026-09-17 |
| CVE-2026-90599 | A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affec | LOW | 2.1 | 6%ile | NVD | 2026-09-13 |
| CVE-2026-18421 | Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboar | LOW | 2.1 | 15%ile | NVD | 2026-09-15 |
| CVE-2026-68530 | Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area | LOW | 2.1 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-81923 | In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving | LOW | 2.1 | 14%ile | NVD | 2026-09-15 |
| CVE-2026-81924 | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation featu | LOW | 2.1 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-18422 | Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in th | LOW | 2.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-18425 | Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\Sitem | LOW | 2.1 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-81925 | Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages | LOW | 2.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-92383 | A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserControl | LOW | 2.1 | 10%ile | NVD | 2026-09-16 |
| CVE-2026-93531 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vu | LOW | 2.1 | — | NVD | 2026-09-18 |
| CVE-2026-18426 | Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control | LOW | 2.0 | 14%ile | NVD | 2026-09-15 |