VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 429 of 479
  • CVE-2026-12409MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the…

  • CVE-2026-26718CriJul 15, 2026
    risk 0.00cvss 9.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP…

  • CVE-2026-20296HigJul 15, 2026
    risk 0.00cvss 8.3epss 0.00

    In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18, and 10.1.2507.24, an attacker could trick a user that holds a role with the `list_deployment_server` capability…

  • CVE-2026-47158HigJul 15, 2026
    risk 0.00cvss 8.3epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left…

  • CVE-2026-52100HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the uploadPutHandler function

  • CVE-2026-58476HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.00

    Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET…

  • CVE-2026-58489MedJul 13, 2026
    risk 0.00cvss epss 0.00

    HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2  state  value but only checked that it was present rather than validating it against the value expected for the user's session.…

  • CVE-2026-61502MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to code execution -…

  • CVE-2026-61956HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی ووکامرس و باسلام: from n/a…

  • CVE-2026-57786HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.

  • CVE-2026-6440MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles…

  • CVE-2026-15070HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for…

  • CVE-2026-58143HigJul 9, 2026
    risk 0.00cvss 8.8epss 0.00

    Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into submitting a forged POST request to the admin.php config update handler,…

  • CVE-2026-59148HigJul 9, 2026
    risk 0.00cvss 8.8epss 0.00

    Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: *…

  • CVE-2026-4275HigJul 9, 2026
    risk 0.00cvss 8.8epss 0.00

    The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and…

  • CVE-2026-5923MedJul 8, 2026
    risk 0.00cvss epss 0.00

    Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.

  • CVE-2026-15034MedJul 8, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public…

  • CVE-2026-9731MedJul 8, 2026
    risk 0.00cvss 4.3epss 0.00

    The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce validation on the plugin_settings function. This makes it possible for unauthenticated attackers to update the…

  • CVE-2026-58315MedJul 7, 2026
    risk 0.00cvss 4.3epss 0.00

    Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged into Web Config, unintended operations may be performed.

  • CVE-2026-34171HigJul 7, 2026
    risk 0.00cvss 8.0epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an attacker-known invitation UUID, allowing an attacker who can…