Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,479 CVEs tagged with CWE-352144 Critical, 3,407 High, 5,741 Medium, 184 Low, 3 Unrated.

CVE-2026-65944

Published Jul 29, 2026

Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

CVSS N/A · Unrated
evidence mentions
1

CVE-2026-9720

Published Jul 29, 2026

The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or inco…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-47725

Published Jul 28, 2026

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the reque…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-15136

Published Jul 28, 2026

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due t…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-66474

Published Jul 27, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-66428

Published Jul 27, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15212

Published Jul 23, 2026

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request()…

CVSS 8.8 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-65540

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65539

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65536

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65512

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65488

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65471

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65464

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65460

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-61981

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57785

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57784

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-57626

Published Jul 23, 2026

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24537

Published Jul 23, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65757

Published Jul 23, 2026

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to auth…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64876

Published Jul 23, 2026

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64871

Published Jul 23, 2026

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid t…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-64791

Published Jul 22, 2026

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall proces…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63684

Published Jul 22, 2026

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator ac…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 9,479 CVEsPage 1 of 380