Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,429 CVEs tagged with CWE-352140 Critical, 3,377 High, 5,723 Medium, 183 Low, 6 Unrated.

CVE-2026-40326

Published May 6, 2026

Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in `csettings.cfc` does not properly validate anti-CSRF tokens…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40325

Published May 6, 2026

Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` function does not properly validate anti-CSRF tokens for content…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40309

Published May 6, 2026

Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function does not validate anti-CSRF tokens for trash management requ…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40174

Published May 6, 2026

Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does not properly validate anti-CSRF tokens for user…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-31957

Published May 6, 2026

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2026-6702

Published May 5, 2026

The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validat…

CVSS 6.1 · Medium
evidence mentions
7
Buzz score
30.8

CVE-2026-6701

Published May 5, 2026

The addfreespace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.3. This is due to missing or incorrect nonce validation…

CVSS 4.3 · Medium
evidence mentions
11
Buzz score
34.9

CVE-2026-6700

Published May 5, 2026

The DX Sources plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation o…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-42091

Published May 4, 2026

goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-3772

Published May 1, 2026

The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add…

CVSS 8.8 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-3140

Published May 1, 2026

The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.14. This is due to a flawed nonce validation cond…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-36960

Published Apr 30, 2026

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanis…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2018-25310

Published Apr 29, 2026

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands…

CVSS 5.3 · Medium

CVE-2018-25298

Published Apr 29, 2026

Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewe…

CVSS 6.9 · Medium

CVE-2026-42645

Published Apr 29, 2026

Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inv…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-38934

Published Apr 27, 2026

Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information vi…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7108

Published Apr 27, 2026

A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery.…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-41425

Published Apr 24, 2026

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_clie…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3565

Published Apr 24, 2026

The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to a missing nonce verification in the taqnix_…

CVSS 4.3 · Medium
evidence mentions
8
Buzz score
32.0

CVE-2026-41317

Published Apr 24, 2026

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is pro…

CVSS 6.6 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-27841

Published Apr 24, 2026

A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Becaus…

CVSS 8.4 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-41347

Published Apr 23, 2026

OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers c…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-40471

Published Apr 23, 2026

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Showing 301-325 of 9,429 CVEsPage 13 of 378