Cross-Site Request Forgery

CWE-352 · 8 records · 5 with a public proof-of-concept

Records the NVD classes as Cross-Site Request Forgery (CWE-352), highest CVSS first.

  1. CRITICAL 9.6CVE-2026-70376public PoC

    Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-60009public PoC

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp,

    theia

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.1CVE-2026-7444

    The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-71273public PoC

    OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the parameter is absent from the request, an else-branch silently clears the device's web admin password to an empty s

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 4.3CVE-2026-17515

    The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport:

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 4.3CVE-2026-16613

    The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luri

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 4.3CVE-2026-18819public PoC

    A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. Th

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-66884public PoC

    Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. This vulnerability is associa

    AI risk analysis on Exploit-DB.ai →