Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,489 CVEs tagged with CWE-352144 Critical, 3,413 High, 5,745 Medium, 185 Low, 2 Unrated.

CVE-2025-67651

Published Jul 31, 2026

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacke…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-66416

Published Jul 30, 2026

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excl…

CVSS 8.6 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-44613

Published Jul 30, 2026

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bod…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-28813

Published Jul 30, 2026

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-5219

Published Jul 30, 2026

Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce P…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-5582

Published Jul 30, 2026

The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-17936

Published Jul 30, 2026

Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigat…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-2482

Published Jul 29, 2026

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-65947

Published Jul 29, 2026

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-65944

Published Jul 29, 2026

Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9720

Published Jul 29, 2026

The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or inco…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-14234

Published Jul 29, 2026

The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker to trick a logged-in administ…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-47725

Published Jul 28, 2026

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the reque…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-15136

Published Jul 28, 2026

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due t…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-66474

Published Jul 27, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-66428

Published Jul 27, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15212

Published Jul 23, 2026

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request()…

CVSS 8.8 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-65540

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-65539

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-65536

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-65512

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-65488

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-65471

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-65464

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-65460

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Showing 1-25 of 9,489 CVEsPage 1 of 380