Skip to main content

CWE archive

CWE-352 CVEs

Programmatic archive

9,459 CVEs tagged with CWE-352143 Critical, 3,389 High, 5,736 Medium, 184 Low, 7 Unrated.

CVE-2026-1673

Published Apr 8, 2026

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-1672

Published Apr 8, 2026

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-39710

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Cross Site Request Forgery.This issue affects RT-Theme 18 | Extensions: f…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39671

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout allows Cross Site Request Forgery.This issu…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39641

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in Skywarrior Blackfyre blackfyre allows Cross Site Request Forgery.This issue affects Blackfyre: from n/a through <= 2.5.4.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39640

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-39635

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand Magazine: from n/a through <=…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39634

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request Forgery.This issue affects Grand Portfolio: from n/a through…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39633

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Car Rental grandcarrental allows Cross Site Request Forgery.This issue affects Grand Car Rental: from n/a throu…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39632

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.This issue affects Grand Blog: from n/a through <= 3.1.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39621

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39620

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a throu…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-39619

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-39618

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in themearile NewsExo newsexo allows Cross Site Request Forgery.This issue affects NewsExo: from n/a through <= 7.1.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39617

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-39603

Published Apr 8, 2026

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a t…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-4141

Published Apr 8, 2026

The Quran Translations plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing nonce validation in the q…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-3499

Published Apr 8, 2026

The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 through 13.5.2…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-4401

Published Apr 8, 2026

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods in `class-dlm-downloads-path.…

CVSS 5.4 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-39371

Published Apr 7, 2026

RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their inte…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34904

Published Apr 7, 2026

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Butto…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-34896

Published Apr 7, 2026

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construc…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-35181

Published Apr 6, 2026

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35180

Published Apr 6, 2026

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token valida…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5624

Published Apr 6, 2026

A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request f…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0
Showing 401-425 of 9,459 CVEsPage 17 of 379