29 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-65944 | Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 | HIGH | 8.8 | 3%ile | NVD | 2026-07-29 |
| CVE-2026-28813 | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommende | HIGH | 8.8 | 4%ile | NVD | 2026-07-30 |
| CVE-2026-50986 | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment valid | HIGH | 8.8 | 3%ile | NVD | 2026-07-31 |
| CVE-2026-15988 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request F | HIGH | 8.8 | 12%ile | NVD | 2026-08-01 |
| CVE-2026-69082 | CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. Th | HIGH | 8.8 | 12%ile | NVD | 2026-08-03 |
| CVE-2026-66416 | Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform stat | HIGH | 8.6 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-5219 | Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows C | HIGH | 8.3 | 3%ile | NVD | 2026-07-30 |
| CVE-2026-48060 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which | HIGH | 8.1 | 21%ile | NVD | 2026-07-28 |
| CVE-2024-34069 | Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution | HIGH | 7.5 | 88%ile | Microsoft | 2024-05-14 |
| CVE-2026-65947 | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 | HIGH | 7.3 | 3%ile | NVD | 2026-07-29 |
| CVE-2026-14234 | The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowin | HIGH | 7.1 | 1%ile | NVD | 2026-07-29 |
| CVE-2026-69093 | Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe | HIGH | 7.1 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-47725 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every | MEDIUM | 6.9 | 5%ile | NVD | 2026-07-28 |
| CVE-2025-67651 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF | MEDIUM | 6.9 | 6%ile | NVD | 2026-07-31 |
| CVE-2026-17936 | Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced | MEDIUM | 6.5 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-66883 | Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu | MEDIUM | 6.3 | — | NVD | 2026-08-04 |
| CVE-2026-44613 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin | MEDIUM | 6.1 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-15344 | The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver | MEDIUM | 4.9 | 28%ile | NVD | 2026-07-29 |
| CVE-2026-16729 | undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before | MEDIUM | 4.8 | 7%ile | NVD | 2026-07-29 |
| CVE-2026-67617 | Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al | MEDIUM | 4.8 | 6%ile | NVD | 2026-08-03 |
| CVE-2026-9720 | The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions | MEDIUM | 4.3 | 3%ile | NVD | 2026-07-29 |
| CVE-2026-5582 | The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24 | MEDIUM | 4.3 | 3%ile | NVD | 2026-07-30 |
| CVE-2025-14469 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, | MEDIUM | 4.3 | 3%ile | NVD | 2026-08-01 |
| CVE-2026-2482 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which c | LOW | 3.1 | 0%ile | NVD | 2026-07-29 |
| CVE-2026-66884 | Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback mod | LOW | 2.1 | — | NVD | 2026-08-04 |
| CVE-2026-14239 | The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken fro | UNKNOWN | — | 3%ile | NVD | 2026-07-30 |
| CVE-2026-13729 | The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrat | UNKNOWN | — | 1%ile | NVD | 2026-08-01 |
| CVE-2026-12586 | The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset | UNKNOWN | — | 2%ile | NVD | 2026-08-02 |
| CVE-2026-16292 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta | UNKNOWN | — | 1%ile | NVD | 2026-08-02 |