Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,459 CVEs tagged with CWE-352143 Critical, 3,389 High, 5,736 Medium, 184 Low, 7 Unrated.

CVE-2026-6589

Published Apr 20, 2026

A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-40948

Published Apr 18, 2026

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-40581

Published Apr 18, 2026

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-40458

Published Apr 17, 2026

PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically submit a fo…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-6451

Published Apr 17, 2026

The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation…

CVSS 4.3 · Medium
evidence mentions
19
Buzz score
36.5

CVE-2025-15635

Published Apr 15, 2026

Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Ord…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-53444

Published Apr 15, 2026

Cross-Site Request Forgery (CSRF) vulnerability in DeluxeThemes Userpro userpro allows Cross Site Request Forgery.This issue affects Userpro: from n/a through < 5.1.11.

CVSS 4.3 · Medium

CVE-2026-1852

Published Apr 15, 2026

The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incor…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-40764

Published Apr 15, 2026

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: f…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-28741

Published Apr 15, 2026

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker t…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4091

Published Apr 15, 2026

The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.0. This is due to missing nonce verification on the setti…

CVSS 6.1 · Medium
evidence mentions
9
Buzz score
29.5

CVE-2026-4002

Published Apr 15, 2026

The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8. This is due to missing nonce validation in the ajax_revoke…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-6293

Published Apr 15, 2026

The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing n…

CVSS 4.3 · Medium
evidence mentions
9
Buzz score
29.5

CVE-2026-40041

Published Apr 13, 2026

Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in authenticated user context by exploiting missing CSRF protec…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2019-25708

Published Apr 12, 2026

Heatmiser Wifi Thermostat 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials by tricking authenticated users into su…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25693

Published Apr 12, 2026

ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keywords par…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2026-6109

Published Apr 12, 2026

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/inde…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-1924

Published Apr 10, 2026

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.4. This is due to missing nonce verification on…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-39848

Published Apr 9, 2026

Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote atta…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-70811

Published Apr 9, 2026

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management functionality.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-70810

Published Apr 9, 2026

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2026-34721

Published Apr 8, 2026

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and Facebook external credentials…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0811

Published Apr 8, 2026

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect no…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
20.4
Showing 376-400 of 9,459 CVEsPage 16 of 379