CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,392 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 186 of 188
- CVE-2026-60648HIGHCVSS 8.0EG 8.02026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privil…
- CVE-2026-60650HIGHCVSS 8.0EG 8.02026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privil…
- CVE-2026-60658HIGHCVSS 7.5EG 7.52026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated …
- CVE-2026-60664HIGHCVSS 8.8EG 8.82026-07-21
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2026-60685MEDIUMCVSS 6.1EG 6.12026-07-21
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…
- CVE-2026-6075HIGHCVSS 8.1EG 8.12026-05-29
The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This ma…
- CVE-2026-60842MEDIUMCVSS 6.1EG 6.12026-07-21
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with networ…
- CVE-2026-60886HIGHCVSS 7.6EG 7.62026-07-21
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-60911MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…
- CVE-2026-60957MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-60962MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker w…
- CVE-2026-61082MEDIUMCVSS 6.5EG 6.52026-07-21
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multipl…
- CVE-2026-6109MEDIUMCVSS 4.3EG 4.32026-04-12
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environment/minecraft/mineflayer/index.js of the component Mineflayer HTTP API. Executing a manip…
- CVE-2026-61097CRITICALCVSS 9.6EG 9.62026-07-21
Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows un…
- CVE-2026-61101HIGHCVSS 8.2EG 8.22026-07-21
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticate…
- CVE-2026-61132HIGHCVSS 7.6EG 7.62026-07-21
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with ne…
- CVE-2026-61204CRITICALCVSS 9.0EG 9.02026-07-21
Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged atta…
- CVE-2026-61217MEDIUMCVSS 6.4EG 6.42026-07-21
Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with ne…
- CVE-2026-61253MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker…
- CVE-2026-61502MEDIUMCVSS 4.3EG 4.32026-07-13
Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configurat…
- CVE-2026-61956HIGHCVSS 7.1EG 7.12026-07-13
Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery.This issue affects ووسلام – همگام سازی …
- CVE-2026-61981MEDIUMCVSS 5.4EG 5.42026-07-23
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
- CVE-2026-62236MEDIUMCVSS 5.4EG 5.42026-07-17
grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti…
- CVE-2026-62443HIGHCVSS 7.1EG 7.12026-07-21
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2026-62487MEDIUMCVSS 6.1EG 6.12026-07-21
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attack…
- CVE-2026-62563MEDIUMCVSS 5.4EG 5.42026-07-21
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2026-6292MEDIUMCVSS 4.3EG 4.32026-06-24
The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely broken nonce validation in the enter_mpclp_login_options() function, w…
- CVE-2026-6293MEDIUMCVSS 4.3EG 4.32026-04-15
The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combi…
- CVE-2026-6294MEDIUMCVSS 4.3EG 4.32026-04-22
The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay_option() function, which handles the plugin settings…
- CVE-2026-63265HIGHCVSS 8.0EG 8.02026-07-22
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching compo…
- CVE-2026-63280HIGHCVSS 8.8EG 8.82026-07-22
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
- CVE-2026-63684HIGHCVSS 8.8EG 8.82026-07-22
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consi…
- CVE-2026-6391MEDIUMCVSS 6.1EG 6.12026-05-20
The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the create_admin_page(…
- CVE-2026-6395MEDIUMCVSS 6.1EG 6.12026-05-20
The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of nonce verification on the settings save h…
- CVE-2026-6396MEDIUMCVSS 4.3EG 4.32026-04-22
The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce verification in the saveFields() function, which handles the fff_save_setti…
- CVE-2026-6400MEDIUMCVSS 4.3EG 4.32026-05-20
The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the options() function, which handles plugin set…
- CVE-2026-6401MEDIUMCVSS 4.3EG 4.32026-05-20
The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing nonce verification on the plugin's settings update forms handled in bottom-bar-admin.php. Non…
- CVE-2026-6405MEDIUMCVSS 4.3EG 4.32026-05-20
The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in versions up to and including 0.3.6. This is due to missing nonce veri…
- CVE-2026-6440MEDIUMCVSS 4.3EG 4.32026-07-10
The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the res…
- CVE-2026-6451MEDIUMCVSS 4.3EG 4.32026-04-17
The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation on all eight AJAX deletion handlers: vehicles_cfmw_d_vehicle…
- CVE-2026-6452MEDIUMCVSS 4.3EG 4.32026-05-20
The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the bigfishgames_syndicate_submenu() function. T…
- CVE-2026-6455HIGHCVSS 8.1EG 8.12026-05-28
The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing n…
- CVE-2026-64791HIGHCVSS 8.8EG 8.82026-07-22
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and i…
- CVE-2026-64821MEDIUMCVSS 4.3EG 4.32026-07-21
djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users by exploiting order-cancellation logic i…
- CVE-2026-64871MEDIUMCVSS 5.4EG 5.42026-07-23
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.
- CVE-2026-64876HIGHCVSS 8.8EG 8.82026-07-23
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
- CVE-2026-65460MEDIUMCVSS 4.3EG 4.32026-07-23
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
- CVE-2026-65464MEDIUMCVSS 5.4EG 5.42026-07-23
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
- CVE-2026-65471CRITICALCVSS 9.6EG 9.62026-07-23
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
- CVE-2026-65488HIGHCVSS 7.1EG 7.12026-07-23
Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →