← Back to feed Search feed

CWE-352 Cross-Site Request Forgery (CSRF) vulnerabilities

68 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2025-15399IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croCRITICAL10.0NVD2026-09-18
CVE-2026-77006The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capaCRITICAL9.68%ileNVD2026-09-12
CVE-2026-59160Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts itHIGH8.835%ileNVD2026-09-15
CVE-2026-78295Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.HIGH8.84%ileNVD2026-09-17
CVE-2026-18110Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint HIGH8.716%ileNVD2026-09-15
CVE-2026-81568Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-HIGH8.726%ileNVD2026-09-15
CVE-2026-92580In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClieHIGH8.764%ileNVD2026-09-16
CVE-2026-19535Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative weHIGH8.616%ileNVD2026-09-16
CVE-2026-40857WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. THIGH8.49%ileNVD2026-09-16
CVE-2026-54507Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5HIGH8.425%ileNVD2026-09-17
CVE-2026-93456django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing HIGH8.45%ileNVD2026-09-18
CVE-2026-92591Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makesHIGH8.215%ileNVD2026-09-16
CVE-2026-61593djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH8.18%ileNVD2026-09-16
CVE-2026-81897In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not valiHIGH7.79%ileNVD2026-09-15
CVE-2026-85385Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output enHIGH7.736%ileNVD2026-09-16
CVE-2026-54087EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFieHIGH7.623%ileNVD2026-09-14
CVE-2026-53660Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializesHIGH7.427%ileNVD2026-09-15
CVE-2026-81090The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate theHIGH7.219%ileNVD2026-09-12
CVE-2026-92751CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing HIGH7.26%ileNVD2026-09-16
CVE-2026-92806phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form haHIGH7.26%ileNVD2026-09-16
CVE-2026-81429The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its templateHIGH7.10%ileNVD2026-09-12
CVE-2026-81902Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBloHIGH7.18%ileNVD2026-09-14
CVE-2026-78081Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0HIGH7.15%ileNVD2026-09-15
CVE-2026-92582AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.jsHIGH7.12%ileNVD2026-09-16
CVE-2026-66571Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.HIGH7.11%ileNVD2026-09-17
CVE-2026-54510Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, theHIGH7.14%ileNVD2026-09-17
CVE-2026-76856Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_configHIGH7.06%ileNVD2026-09-15
CVE-2026-50025Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, MousMEDIUM6.98%ileNVD2026-09-11
CVE-2026-90543WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a misMEDIUM6.928%ileNVD2026-09-12
CVE-2026-91819Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-secMEDIUM6.95%ileNVD2026-09-15
CVE-2026-92915WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/useMEDIUM6.924%ileNVD2026-09-17
CVE-2026-84023The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomyMEDIUM6.52%ileNVD2026-09-12
CVE-2026-85131The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk aMEDIUM6.58%ileNVD2026-09-16
CVE-2026-49992Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forMEDIUM6.35%ileNVD2026-09-11
CVE-2026-81907Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function MEDIUM6.112%ileNVD2026-09-11
CVE-2026-62280Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoinMEDIUM6.112%ileNVD2026-09-15
CVE-2026-81912Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboardMEDIUM5.78%ileNVD2026-09-11
CVE-2026-62133Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.MEDIUM5.43%ileNVD2026-09-11
CVE-2026-17047IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper reqMEDIUM5.42%ileNVD2026-09-14
CVE-2026-74005Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.MEDIUM5.41%ileNVD2026-09-17
CVE-2026-80355Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerabiMEDIUM5.411%ileNVD2026-09-17
CVE-2026-54613Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5MEDIUM5.415%ileNVD2026-09-17
CVE-2026-68526Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concretMEDIUM5.38%ileNVD2026-09-11
CVE-2026-91857Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affecMEDIUM5.37%ileNVD2026-09-15
CVE-2026-52823Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}MEDIUM5.312%ileNVD2026-09-15
CVE-2026-92579In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without MEDIUM5.35%ileNVD2026-09-16
CVE-2026-54642CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-MEDIUM5.313%ileNVD2026-09-17
CVE-2026-82764Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page whMEDIUM5.14%ileNVD2026-09-14
CVE-2026-90893MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setMEDIUM5.18%ileNVD2026-09-14
CVE-2026-62139Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.MEDIUM4.31%ileNVD2026-09-11
CVE-2026-84024The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowinMEDIUM4.31%ileNVD2026-09-12
CVE-2026-91009The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation anMEDIUM4.31%ileNVD2026-09-17
CVE-2026-77568Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, aMEDIUM4.2NVD2026-09-18
CVE-2026-68532Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cLOW2.39%ileNVD2026-09-15
CVE-2026-81919Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() acLOW2.36%ileNVD2026-09-15
CVE-2026-81920Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reseLOW2.39%ileNVD2026-09-15
CVE-2026-81637Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim'LOW2.340%ileNVD2026-09-17
CVE-2026-90599A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affecLOW2.16%ileNVD2026-09-13
CVE-2026-18421Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboarLOW2.115%ileNVD2026-09-15
CVE-2026-68530Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards areaLOW2.117%ileNVD2026-09-15
CVE-2026-81923In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before savingLOW2.114%ileNVD2026-09-15
CVE-2026-81924Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation featuLOW2.18%ileNVD2026-09-15
CVE-2026-18422Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in thLOW2.131%ileNVD2026-09-15
CVE-2026-18425Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemLOW2.16%ileNVD2026-09-15
CVE-2026-81925Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messagesLOW2.131%ileNVD2026-09-15
CVE-2026-92383A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserControlLOW2.110%ileNVD2026-09-16
CVE-2026-93531A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vuLOW2.1NVD2026-09-18
CVE-2026-18426Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's controlLOW2.014%ileNVD2026-09-15