Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,451 CVEs tagged with CWE-352143 Critical, 3,385 High, 5,730 Medium, 184 Low, 9 Unrated.

CVE-2026-6294

Published Apr 22, 2026

The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gp…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-4140

Published Apr 22, 2026

The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.1.6. This is due to missing nonce validation…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-4139

Published Apr 22, 2026

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verificatio…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
30.8

CVE-2026-4138

Published Apr 22, 2026

The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation on t…

CVSS 4.3 · Medium
evidence mentions
9
Buzz score
33.0

CVE-2026-4133

Published Apr 22, 2026

The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.7. This is due to missing nonce validation in the…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-4131

Published Apr 22, 2026

The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the a…

CVSS 6.1 · Medium
evidence mentions
11
Buzz score
34.9

CVE-2026-4121

Published Apr 22, 2026

The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.1. This is due to missing nonce validation in the plugin's se…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
30.8

CVE-2026-4118

Published Apr 22, 2026

The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.3. This is due to missing nonce validation in…

CVSS 4.3 · Medium
evidence mentions
9
Buzz score
33.0

CVE-2026-4090

Published Apr 22, 2026

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing nonce verification in the rd_…

CVSS 6.1 · Medium
evidence mentions
17
Buzz score
38.9

CVE-2026-40929

Published Apr 21, 2026

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mutating JSON endpoint that deletes comments but performs no…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40928

Published Apr 21, 2026

WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/` accept state-changing requests via `$_REQUEST`/`$_GET` an…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40926

Published Apr 21, 2026

WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, a…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40925

Published Apr 21, 2026

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site s…

CVSS 8.3 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40883

Published Apr 21, 2026

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41194

Published Apr 21, 2026

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /mailbox/oauth-disconnect/{id}/{…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-31014

Published Apr 21, 2026

Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing requests without requiring a CSRF t…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6589

Published Apr 20, 2026

A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-40948

Published Apr 18, 2026

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-40581

Published Apr 18, 2026

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-40458

Published Apr 17, 2026

PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically submit a fo…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-6451

Published Apr 17, 2026

The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation…

CVSS 4.3 · Medium
evidence mentions
19
Buzz score
40.0

CVE-2025-15635

Published Apr 15, 2026

Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Ord…

CVSS 4.3 · Medium

CVE-2025-53444

Published Apr 15, 2026

Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a through < 5.1.11.

CVSS 4.3 · Medium
Showing 351-375 of 9,451 CVEsPage 15 of 379