← Back to feed Search feed

CWE-352 Cross-Site Request Forgery (CSRF) vulnerabilities

29 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-65944Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0HIGH8.83%ileNVD2026-07-29
CVE-2026-28813Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommendeHIGH8.84%ileNVD2026-07-30
CVE-2026-50986PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validHIGH8.83%ileNVD2026-07-31
CVE-2026-15988The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request FHIGH8.812%ileNVD2026-08-01
CVE-2026-69082CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. ThHIGH8.812%ileNVD2026-08-03
CVE-2026-66416Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform statHIGH8.66%ileNVD2026-07-30
CVE-2026-5219Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows CHIGH8.33%ileNVD2026-07-30
CVE-2026-48060Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances whichHIGH8.121%ileNVD2026-07-28
CVE-2024-34069Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command executionHIGH7.588%ileMicrosoft2024-05-14
CVE-2026-65947Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2HIGH7.33%ileNVD2026-07-29
CVE-2026-14234The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowinHIGH7.11%ileNVD2026-07-29
CVE-2026-69093Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs peHIGH7.12%ileNVD2026-08-03
CVE-2026-47725nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every MEDIUM6.95%ileNVD2026-07-28
CVE-2025-67651A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF MEDIUM6.96%ileNVD2026-07-31
CVE-2026-17936Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convincedMEDIUM6.58%ileNVD2026-07-30
CVE-2026-66883Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize moduMEDIUM6.3NVD2026-08-04
CVE-2026-44613Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin MEDIUM6.17%ileNVD2026-07-30
CVE-2026-15344The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all verMEDIUM4.928%ileNVD2026-07-29
CVE-2026-16729undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before MEDIUM4.87%ileNVD2026-07-29
CVE-2026-67617Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that alMEDIUM4.86%ileNVD2026-08-03
CVE-2026-9720The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions MEDIUM4.33%ileNVD2026-07-29
CVE-2026-5582The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24MEDIUM4.33%ileNVD2026-07-30
CVE-2025-14469The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, MEDIUM4.33%ileNVD2026-08-01
CVE-2026-2482IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which cLOW3.10%ileNVD2026-07-29
CVE-2026-66884Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback modLOW2.1NVD2026-08-04
CVE-2026-14239The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken froUNKNOWN3%ileNVD2026-07-30
CVE-2026-13729The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administratUNKNOWN1%ileNVD2026-08-01
CVE-2026-12586The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-resetUNKNOWN2%ileNVD2026-08-02
CVE-2026-16292The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metaUNKNOWN1%ileNVD2026-08-02