<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Cross-Site Request Forgery (CSRF) (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/csrf.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/csrf-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Cross-Site Request Forgery (CSRF) (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-6075 – The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6075</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6075</strong></p>
  <p>The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45343 – LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45343</guid>
    <pubDate>Thu, 28 May 2026 22:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45343</strong></p>
  <p>LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScript in an administrator's browser session. This affects instances configured with SSO/OAuth authentication, which is one of the supported authentication methods in LinkAce. An attacker who sets their OA…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44657 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44657</guid>
    <pubDate>Thu, 28 May 2026 21:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44657</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in 2.28.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6455 – The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6455</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6455</strong></p>
  <p>The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only executed when _wpnonce is present in the POST body, allowing it to be trivially…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39436 – Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39436</guid>
    <pubDate>Mon, 25 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39436</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery.  This issue affects CformsII: from n/a through 15.1.3.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41074 – RT is an open source, enterprise-grade issue and ticket tracking system. Version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41074</guid>
    <pubDate>Fri, 22 May 2026 22:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41074</strong></p>
  <p>RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that user's behalf. This issue has been fixed in version 6.0.3.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8434 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8434</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8434</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8433 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8433</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8433</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8432 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8432</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8432</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8427 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8427</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8427</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8416 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8416</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8416</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8415 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8415</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8415</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8414 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8414</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8414</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8413 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8413</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8413</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8412 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8412</guid>
    <pubDate>Thu, 21 May 2026 22:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8412</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at 	concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8411 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8411</guid>
    <pubDate>Thu, 21 May 2026 22:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8411</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8410 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8410</guid>
    <pubDate>Thu, 21 May 2026 22:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8410</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8409 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8409</guid>
    <pubDate>Thu, 21 May 2026 22:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8409</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8428 – Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.ph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8428</guid>
    <pubDate>Thu, 21 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8428</strong></p>
  <p>Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never calls $this->token->validate('do_update'). The form is rendered as a POST form, meaning the token reaches the browser, but because the controller discards it withou…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8426 – Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8426</guid>
    <pubDate>Thu, 21 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8426</strong></p>
  <p>Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for a known marketplace item ID can overwrite the package PHP on disk and force its upgrade() method to execute in a single browser navigation. This results in remote code execution as the web s…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8421 – Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_packag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8421</guid>
    <pubDate>Thu, 21 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8421</strong></p>
  <p>Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php.  An attacker who can cause an authenticated administrator to visit a crafted page,  and who has placed or caused a package to be present under DIR_PACKAGES/<handle>/, can force the installation of that package without any CSRF protection. Pac…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8417 – Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8417</guid>
    <pubDate>Thu, 21 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8417</strong></p>
  <p>Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete/controllers/single_page/dashboard/extend/update.php checks only canInstallPackages() before executing upgradeCoreData() and upgrade() on the named package's controller. Because the endpoint is a state-changing GET route with n…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39310 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39310</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39310</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron environment, it explicitly disables authentication middleware for the Clipper API, exposin…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44925 – Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44925</guid>
    <pubDate>Wed, 20 May 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44925</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11954 – Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technolog...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11954</guid>
    <pubDate>Wed, 20 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11954</strong></p>
  <p>Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery.  This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8604 – In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8604</guid>
    <pubDate>Tue, 19 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8604</strong></p>
  <p>In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7507 – A session fixation vulnerability was found in Keycloak's login-actions endpoints...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7507</guid>
    <pubDate>Tue, 19 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7507</strong></p>
  <p>A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session handles without adequate CSRF protection or cookie ownership validation—an attacker c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47976 – TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47976</guid>
    <pubDate>Sat, 16 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47976</strong></p>
  <p>TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can authenticate, retrieve a CSRF token from the plugin event page, and upload malicious PHP files to the textpattern/tmp/ directory for code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4094 – The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4094</guid>
    <pubDate>Fri, 15 May 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4094</strong></p>
  <p>The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete the entire multi-currency configuration by visiting any wp-admin page…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28761 – Cross-site request forgery vulnerability exists in Musetheque V4 Information Dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28761</guid>
    <pubDate>Fri, 15 May 2026 06:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28761</strong></p>
  <p>Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected product, unexpected operations may be done.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44364 – MISP modules are autonomous modules that can be used to extend MISP for new serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44364</guid>
    <pubDate>Wed, 13 May 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44364</strong></p>
  <p>MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker to cause an authenticated user to submit unintended requests to the home endpoint. The vulnerability was due to the home blueprint being exempted from CSRF protection. This could allow modification of…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42551 – Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42551</guid>
    <pubDate>Wed, 13 May 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42551</strong></p>
  <p>Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP-Method-Override header and the $_REQUEST['_method'] parameter on any HTTP verb (including safe verbs such as GET), with no opt-in and no whitelist of permitted target methods. A GET request can silently become a DELETE or PUT, enabling CSRF escalation against destructive endpoi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42289 – ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42289</guid>
    <pubDate>Tue, 12 May 2026 23:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42289</strong></p>
  <p>ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token validation. An unauthenticated attacker can craft a malicious HTML page that, when visited by an authenticated administrator, silently elevates any low-privilege user to full administrator or creates a new…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30807 – Cross-Site Request Forgery vulnerability allows an attacker to perform unauthori...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30807</guid>
    <pubDate>Tue, 12 May 2026 16:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30807</strong></p>
  <p>Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45430 – The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45430</guid>
    <pubDate>Tue, 12 May 2026 04:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45430</strong></p>
  <p>The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38566 – HireFlow v1.2 does not implement CSRF token validation on any state-changing POS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38566</guid>
    <pubDate>Mon, 11 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38566</strong></p>
  <p>HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission at /feedback/add/<id>, interview scheduling at /interviews/add) are vulnerable to CSRF. An attacker who can trick an authenticated user into visiting a malicious page can silently change the victim's…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42286 – Emlog is an open source website building system. Prior to version 2.6.11, missin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42286</guid>
    <pubDate>Fri, 08 May 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42286</strong></p>
  <p>Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing unauthorized actions like system registration, plugin management, and configuration changes. This issue has been patched in version 2.6.11.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40326 – Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40326</guid>
    <pubDate>Wed, 06 May 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40326</strong></p>
  <p>Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in `csettings.cfc` does not properly validate anti-CSRF tokens for site bundle creation requests. An attacker can craft a malicious webpage or link that, when visited by a logged-in administrator, triggers the silent creation of a comprehensive site bundle. This bundle is saved to…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40325 – Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40325</guid>
    <pubDate>Wed, 06 May 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40325</strong></p>
  <p>Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` function does not properly validate anti-CSRF tokens for content restoration requests. An attacker can trick a logged-in administrator to submit a forged request that restores deleted items from the trash and places them at an attacker-controlled location in the site structure through…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40309 – Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40309</guid>
    <pubDate>Wed, 06 May 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40309</strong></p>
  <p>Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function does not validate anti-CSRF tokens for trash management requests. An attacker can induce a logged-in administrator to submit a forged request that empties the trash and permanently deletes all deleted content. This can cause irreversible data loss and disrupt recovery of content…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40174 – Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40174</guid>
    <pubDate>Wed, 06 May 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40174</strong></p>
  <p>Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does not properly validate anti-CSRF tokens for user address management operations.  An attacker can induce a logged-in administrator to submit a forged request that adds, modifies, or deletes user address records, including email addresses and phone numbers. This can be…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3772 – The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3772</guid>
    <pubDate>Fri, 01 May 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3772</strong></p>
  <p>The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and 'add_themes_page' functions. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin and theme PHP files with attacker-controlled code via a forged request, granted they can…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36960 – A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36960</guid>
    <pubDate>Thu, 30 Apr 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36960</strong></p>
  <p>A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints. If an authenticated…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36956 – A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36956</guid>
    <pubDate>Thu, 30 Apr 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36956</strong></p>
  <p>A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft a malicious webpage that sends forged HTTP requests to configuration endpoints su…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38934 – Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38934</guid>
    <pubDate>Mon, 27 Apr 2026 17:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38934</strong></p>
  <p>Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41317 – Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subsc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41317</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41317</strong></p>
  <p>Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like exploits. This endpoint writes to database and it is also accessible via GET method. The patch in commit 52ea2f2d1b587be0807557e96f025f47897d00fd restricts method to POST.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27841 – A vulnerability in SenseLive X3050's web management interface allows state-chang...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27841</guid>
    <pubDate>Fri, 24 Apr 2026 00:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27841</strong></p>
  <p>A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Because the application does not enforce server-side validation of request origin or implement CSRF tokens, a malicious external webpage could cause a user's browser to submit unauthorized configuration requests to the device.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41347 – OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41347</guid>
    <pubDate>Thu, 23 Apr 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41347</strong></p>
  <p>OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers can exploit this by sending malicious requests from a browser in trusted-proxy deployments to perform unauthorized actions on HTTP operator endpoints.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40471 – hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40471</guid>
    <pubDate>Thu, 23 Apr 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40471</strong></p>
  <p>hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4922 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4922</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4922</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40926 – WWBN AVideo is an open source video platform. In versions 29.0 and prior, three ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40926</guid>
    <pubDate>Tue, 21 Apr 2026 23:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40926</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only a role check (`Category::canCreateCategory()` / `User::isAdmin()`) and perform state-changing actions against the database without calling `isGlobalTokenValid()`…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40909 – WWBN AVideo is an open source video platform. In versions 29.0 and prior, the lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40909</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40909</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['code']` parameter is then written verbatim to that path via `fwrite()` at line 40. An admin attacker (or any user who can CSRF an admin, since no CSRF…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40883 – goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40883</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40883</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as ?delete and ?mkdir because goshs relies on HTTP basic auth alone and performs no CSRF, Origin, or Referer validation for those ro…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40875 – mailcow: dockerized is an open source groupware/email suite based on docker. In ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40875</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40875</strong></p>
  <p>mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the server trusts the X-Real-IP header as the source IP for logging, an attacker can inject HTML/JS into this field. This Self-XSS can be exploited by a Lo…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40497 – FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40497</guid>
    <pubDate>Tue, 21 Apr 2026 03:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40497</strong></p>
  <p>FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<object>` but does NOT strip `<style>` tags. The mailbox signature field is saved via POST /mailbox/settings/{id} and later rendered unescaped via `{!! $conversation->getSignatureProcessed([], true) !!}` in conversation views…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40581 – ChurchCRM is an open-source church management system. In versions prior to 7.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40581</guid>
    <pubDate>Sat, 18 Apr 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40581</strong></p>
  <p>ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET request with no CSRF token validation. An attacker can craft a malicious page that, when visited by an authenticated administrator, silently triggers deletion of…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40484 – ChurchCRM is an open-source church management system. In versions prior to 7.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40484</guid>
    <pubDate>Sat, 18 Apr 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40484</strong></p>
  <p>ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document root using recursiveCopyDirectory(), which performs no file extension filtering. An authenticated administrator can upload a crafted backup archive containing a PH…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14868 – The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14868</guid>
    <pubDate>Thu, 16 Apr 2026 08:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14868</strong></p>
  <p>The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform_options_page_html' function. This makes it possible for unauthenticated attackers to delete arbitrary f…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40764 – Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40764</guid>
    <pubDate>Wed, 15 Apr 2026 11:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40764</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4162 – The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4162</guid>
    <pubDate>Fri, 10 Apr 2026 10:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4162</strong></p>
  <p>The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to uninstall and deactivate the plugin and delete plugin options. NOTE: This vulnerability i…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70810 – Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70810</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70810</strong></p>
  <p>Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39394 – CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39394</guid>
    <pubDate>Wed, 08 Apr 2026 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39394</strong></p>
  <p>CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Install::index() controller reads the host POST parameter without any validation and passes it directly into updateEnvSettings(), which writes it into the .env file via preg_replace(). Because newline characters in the value are not s…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-93</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39671 – Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39671</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39671</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout allows Cross Site Request Forgery.This issue affects Extra Fees Plugin for WooCommerce: from n/a through <= 4.3.3.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39640 – Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39640</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39640</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39621 – Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicep...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39621</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39621</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39620 – Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39620</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39620</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39619 – Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39619</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39619</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39617 – Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39617</guid>
    <pubDate>Wed, 08 Apr 2026 09:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39617</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3499 – The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3499</guid>
    <pubDate>Wed, 08 Apr 2026 02:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3499</strong></p>
  <p>The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 13.4.6 through 13.5.2.1. This is due to missing or incorrect nonce validation on the ajax_migrate_to_custom_post_type, ajax_adt_clear_custom_attributes_product_meta_keys, ajax_update_file_url_to_lower_case, ajax_use_legacy_filters_and_rules,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34904 – Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34904</guid>
    <pubDate>Tue, 07 Apr 2026 09:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34904</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through 6.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34896 – Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34896</guid>
    <pubDate>Tue, 07 Apr 2026 09:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34896</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34932 – hoppscotch is an open source API development ecosystem. Prior to version 2026.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34932</guid>
    <pubDate>Thu, 02 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34932</strong></p>
  <p>hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This issue has been patched in version 2026.3.0.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34728 – phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the Medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34728</guid>
    <pubDate>Thu, 02 Apr 2026 15:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34728</strong></p>
  <p>phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is triggered, the user-supplied name parameter is concatenated with the base upload directory path without any path traversal validation. The FILTER_SANITIZE_SPECIAL_CHARS filter only encodes HTML special charact…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34394 – WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34394</guid>
    <pubDate>Tue, 31 Mar 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34394</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF token validation. There is no call to isGlobalTokenValid() or verifyToken() before processing the request. Combined with the application's explicit SameSite=None cookie policy, an attacker can forge cross-origin POST requests from a malicious…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33373 – An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33373</guid>
    <pubDate>Mon, 30 Mar 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33373</strong></p>
  <p>An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state transitions. Specifically, tokens generated after operations such as enabling two-factor authentication or changing a password may lack CSRF enforcement.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4315 – A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4315</guid>
    <pubDate>Mon, 30 Mar 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4315</strong></p>
  <p>A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.This issue affects Fireware OS: 11.8 through 11.12.4+541730, 12.0 through 12.11.8, and 2025.1 through 2026.1.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-15604 – Amon2 versions before 6.17 for Perl use an insecure random_string implementation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15604</guid>
    <pubDate>Sat, 28 Mar 2026 19:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-15604</strong></p>
  <p>Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions.  In versions 6.06 through 6.16, the random_string function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes by concatenating a SHA-1 hash seeded with the built-in rand() function, the PID, and the high resolution epoch time.  The PID w…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33918 – OpenEMR is a free and open source electronic health records and medical practice...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33918</guid>
    <pubDate>Thu, 26 Mar 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33918</strong></p>
  <p>OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL permissions. This allows any authenticated OpenEMR user — regardless of whether they have billing pri…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3857 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3857</guid>
    <pubDate>Wed, 25 Mar 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3857</strong></p>
  <p>GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29839 – DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29839</guid>
    <pubDate>Tue, 24 Mar 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29839</strong></p>
  <p>DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33681 – WWBN AVideo is an open source video platform. In versions up to and including 26...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33681</guid>
    <pubDate>Mon, 23 Mar 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33681</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript.json.php` endpoint accepts a `name` parameter via POST and passes it to `Plugin::getDatabaseFileName()` without any path traversal sanitization. This allows an authenticated admin (or an attacker via CSRF) to traverse outside the plugin directory and execute the contents of any…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33649 – WWBN AVideo is an open source video platform. In versions up to and including 26...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33649</guid>
    <pubDate>Mon, 23 Mar 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33649</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets `session.cookie_samesite=None` on session cookies. This allows an unauthenticated attac…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33507 – WWBN AVideo is an open source video platform. In versions up to and including 26...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33507</guid>
    <pubDate>Mon, 23 Mar 2026 17:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33507</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. Combined with the application explicitly setting `session.cookie_samesite = 'None'` for HTTPS connections, an unauthenticated attacker can craft a pa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33479 – WWBN AVideo is an open source video platform. In versions up to and including 26...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33479</guid>
    <pubDate>Mon, 23 Mar 2026 15:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33479</strong></p>
  <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsanitized user input from `$_REQUEST['sections']` array values directly into PHP's `eval()` function. While the endpoint is gated behind `User::isAdmin()`, it has no CSRF token validation. Combined with AVideo's explicit `SameSite=None` session cookie conf…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32989 – Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32989</guid>
    <pubDate>Fri, 20 Mar 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32989</strong></p>
  <p>Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests to a profile update endpoint handling file uploads. Attackers can exploit this to upload executable files to web-accessible locations, leading to arbitrary code execution in the context of the web server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32537 – Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Playe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32537</guid>
    <pubDate>Fri, 20 Mar 2026 10:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32537</strong></p>
  <p>Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Player: from n/a through 5.0.4.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32817 – Admidio is an open-source user management solution. In versions 5.0.0 through 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32817</guid>
    <pubDate>Fri, 20 Mar 2026 02:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32817</strong></p>
  <p>Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folders or files. The folder_delete and file_delete action handlers in modules/documents-files.php only perform a VIEW authorization check (getFolderForDownload / getFileForDownload) before calling delete(), and they…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32756 – Admidio is an open-source user management solution. Versions 5.0.6 and below con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32756</guid>
    <pubDate>Fri, 20 Mar 2026 00:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32756</strong></p>
  <p>Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification interact within UploadHandlerFile.php, an authenticated user with upload permissions can bypass file extension restrictions by intentionally submitti…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55046 – MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55046</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55046</strong></p>
  <p>MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The vulnerable cTrash.empty function lacks CSRF token validation, enabling malicious websites to forge requests that irreversibly delete all trashed content when an authenticated administrator visits a crated webpage. Succe…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55045 – The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55045</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55045</strong></p>
  <p>The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function lacks CSRF token validation, enabling malicious websites to forge requests that add, modify, or delete user addresses when an authenticated administrator visits a crafted webpage. Successful exploitation of the update a…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55044 – The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55044</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55044</strong></p>
  <p>The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cTrash.restore function lacks CSRF token validation, enabling malicious websites to forge requests that restore content to arbitrary parent locations when an authenticated administrator visits a crafted webpage. Successfu…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55041 – MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55041</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55041</strong></p>
  <p>MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privileges by adding any user to any group without proper authorization checks. The vulnerable function lacks CSRF token validation and directly processes user-supplied userId and groupId parameters via getUserManager().create…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55040 – The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55040</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55040</strong></p>
  <p>The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests that install attacker-controlled forms when an authenticated administrator visits a crafted webpage. Full exploitation o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22323 – A CSRF vulnerability in the Link Aggregation configuration interface allows an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22323</guid>
    <pubDate>Wed, 18 Mar 2026 08:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22323</strong></p>
  <p>A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into sending unauthorized POST requests to the device by luring them to a malicious webpage. This can silently alter the device’s configuration without the victim’s knowledge or consent. Availability impact was set to low because after a successful attack the…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32268 – The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32268</guid>
    <pubDate>Wed, 18 Mar 2026 06:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32268</strong></p>
  <p>The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Be…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22202 – wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22202</guid>
    <pubDate>Fri, 13 Mar 2026 19:54:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22202</strong></p>
  <p>wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2626 – The divi-booster WordPress plugin before 5.0.2 does not have authorization and C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2626</guid>
    <pubDate>Wed, 11 Mar 2026 06:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2626</strong></p>
  <p>The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be further exploited when combined with a PHP gadget chain to achieve PHP Object Injection</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28495 – GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28495</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28495</strong></p>
  <p>GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code via the gsconfig editor module. The form lacks CSRF protection, enabling a remote unauthenticated attacker to exploit this via Cross-Site Request Forgery against a logged-i…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28281 – InstantCMS is a free and open source content management system. Prior to 2.18.1,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28281</guid>
    <pubDate>Tue, 10 Mar 2026 17:38:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28281</strong></p>
  <p>InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests on behalf of the user. This vulnerability is fixed in 2.18.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31816 – Budibase is a low code platform for creating internal tools, workflows, and admi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31816</guid>
    <pubDate>Mon, 09 Mar 2026 21:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31816</strong></p>
  <p>Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. The isWebhookEndpoint() function uses an unanchored regex that tests against ctx.request.url, wh…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31816">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
