<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Cross-Site Request Forgery (CSRF)</title>
  <link>https://cvedaily.com/pages/tags/csrf.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/csrf.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Cross-Site Request Forgery (CSRF)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-9732 – The EmergencyWP – Dead Man's switch &amp; legacy deliverance plugin for WordPress is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9732</guid>
    <pubDate>Wed, 03 Jun 2026 00:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9732</strong></p>
  <p>The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the form_settings_ui (settings save handler, procedural include scope) function. This makes it possible for unauthenticated attackers to modify plugin settings including the mi…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42073 – OpenClaude is an open-source coding-agent command line interface for cloud and l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42073</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42073</strong></p>
  <p>OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attacks, the server validates a state parameter against an internally stored value. However, due to a logic flaw in the order of conditionals, an attacker…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34460 – NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34460</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34460</strong></p>
  <p>NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging the authorization code. This allows an attacker to capture a valid OAuth callback URL for their own account and cause a victim's browser to navigate to it, resulting in the victim's session being authenticated as the att…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-302</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9730 – The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9730</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9730</strong></p>
  <p>The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the gmz_comment_settings_save function. This makes it possible for unauthenticated attackers to modify the plugin's comment-display setting via a forged request via a forged request granted they can tr…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9723 – The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9723</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9723</strong></p>
  <p>The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the plusone-lang, plusone-callback, and plusone-url options stored in the dat…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9722 – The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9722</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9722</strong></p>
  <p>The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the addOptionsPageFields function. This makes it possible for unauthenticated attackers to update the plugin's settings, including the API key, tag blacklist, relevance threshold, batch size, and tagging toggles, via a…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9599 – The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9599</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9599</strong></p>
  <p>The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, including the tectite_forms_button option, via a forged request via a forged request granted they can tric…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8422 – The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8422</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8422</strong></p>
  <p>The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated attackers to modify or reset the plugin's per-role meta box visibility settings via a forged request granted th…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4071 – The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4071</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4071</strong></p>
  <p>The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce validation in the birdseed_plugin_settings_page() function. The function processes the 'birdseed_token' GET parameter and saves it to the database via update_option() without verifying a nonce. This makes it possible for unauthenticated attackers…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25435 – ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25435</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25435</strong></p>
  <p>ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafting malicious requests. Attackers can deactivate customer accounts via the admin interface by tricking users into visiting attacker-controlled pages that submit requests to the regstatus endpoint with action=deny parameters.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49433 – The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49433</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49433</strong></p>
  <p>The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-in user into clicking a malicious link, the attacker can change the user's email address and take over their account. Fixed on 2026-05-20.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40549 – SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save cre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40549</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40549</strong></p>
  <p>SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged GET or POST request to the application.  This issue affects SOPlanning version 1.55 and below.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25397 – PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25397</guid>
    <pubDate>Fri, 29 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25397</strong></p>
  <p>PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that automatically submits POST requests to the users.php endpoint with parameters like name, email, password, and permissions set to admin…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25387 – HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25387</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25387</strong></p>
  <p>HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level to modify admin credentials without authentication.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45610 – WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45610</guid>
    <pubDate>Fri, 29 May 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45610</strong></p>
  <p>WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getId(), false) on the session-authenticated user, and returns. There is no forbidIfIsUntrustedRequest() call, no isTokenValid() check, no X-CSRF-Token/S…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6075 – The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6075</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6075</strong></p>
  <p>The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to missing nonce verification on the bulk action handlers in the settings tab handlers. This makes it possible for unauthenticated attackers to trick an administrator into performing bulk delete, edit, or purge operations on plugin settings and attachment…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45343 – LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45343</guid>
    <pubDate>Thu, 28 May 2026 22:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45343</strong></p>
  <p>LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScript in an administrator's browser session. This affects instances configured with SSO/OAuth authentication, which is one of the supported authentication methods in LinkAce. An attacker who sets their OA…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44657 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44657</guid>
    <pubDate>Thu, 28 May 2026 21:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44657</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a valid file_show_inline_token CSRF token on file_download.php, an attacker can execute code by uploading a crafted XHTML attachment referencing a JavaScript attachment. This vulnerability is fixed in 2.28.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9618 – The PeachPay — Payments &amp; Express Checkout for WooCommerce (supports Stripe, Pay...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9618</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9618</strong></p>
  <p>The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.120.46. This is due to missing or incorrect nonce validation on the peachpay_stripe_handle_admin_actions function. This makes it possible for unauthenticated attackers to permanentl…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6455 – The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Sit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6455</guid>
    <pubDate>Thu, 28 May 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6455</strong></p>
  <p>The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only executed when _wpnonce is present in the POST body, allowing it to be trivially…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7533 – The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7533</guid>
    <pubDate>Thu, 28 May 2026 06:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7533</strong></p>
  <p>The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a user-supplied GET parameter without any CSRF token validation. This makes it possible for u…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48147 – Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48147</guid>
    <pubDate>Wed, 27 May 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48147</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/backend-core/src/middleware/matchers.ts route patterns are compiled into unanchored regular expressions and tested against ctx.request.url, which includes the full query string. The CSRF middleware in the Budibase Worker uses this matching system to decide whether to skip CSRF…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-185</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9674 – A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9674</guid>
    <pubDate>Wed, 27 May 2026 15:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9674</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48925 – A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48925</guid>
    <pubDate>Wed, 27 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48925</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30498 – A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30498</guid>
    <pubDate>Wed, 27 May 2026 15:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30498</strong></p>
  <p>A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8942 – The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Reques...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8942</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8942</strong></p>
  <p>The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the metamagic_update_options function. This makes it possible for unauthenticated attackers to modify the plugin's SEO settings, including enabling or disabling the plugin and toggling description and keyword m…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8906 – The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8906</guid>
    <pubDate>Wed, 27 May 2026 08:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8906</strong></p>
  <p>The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as cli…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49001 – Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49001</guid>
    <pubDate>Wed, 27 May 2026 08:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49001</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampering with configuration data.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8943 – The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Reque...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8943</guid>
    <pubDate>Wed, 27 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8943</strong></p>
  <p>The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the gostats_manage() function. This makes it possible for unauthenticated attackers to update the plugin's settings (gostats_siteid and gostats_server options) via a forged request granted they can trick a sit…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8941 – The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8941</guid>
    <pubDate>Wed, 27 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8941</strong></p>
  <p>The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the ossdl_off_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings — including the CDN URL used to rewrite all static asset references on the site — via a forged req…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8939 – The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Reques...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8939</guid>
    <pubDate>Wed, 27 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8939</strong></p>
  <p>The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the search_simple_fields_options() function in functions_admin.php. This makes it possible for unauthenticated attackers to modify the plugin's settings — including post types to search in, custom fields, media fie…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8938 – The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8938</guid>
    <pubDate>Wed, 27 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8938</strong></p>
  <p>The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.3. This is due to missing or incorrect nonce validation on the amJL_certification function. This makes it possible for unauthenticated attackers to update the plugin's license key option, and subsequently trigger license validation and pro feature installation on the…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8911 – The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8911</guid>
    <pubDate>Wed, 27 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8911</strong></p>
  <p>The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as c…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8903 – The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8903</guid>
    <pubDate>Wed, 27 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8903</strong></p>
  <p>The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the ipv_save_changes function. This makes it possible for unauthenticated attackers to modify the plugin's firewall and two-factor authentication settings — including the operating mode…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8708 – The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8708</guid>
    <pubDate>Wed, 27 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8708</strong></p>
  <p>The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the _options_page function. This makes it possible for unauthenticated attackers to update the plugin's breadcrumb configuration, including templates, delimiter, home label, home URI, and breadcrumb rules via a f…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7614 – The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Reque...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7614</guid>
    <pubDate>Wed, 27 May 2026 07:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7614</strong></p>
  <p>The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the OPH_options function. This makes it possible for unauthenticated attackers to update the plugin's configuration settings without authorization via a forged request granted they can trick a site administr…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9236 – The CM Ad Changer – A simple tool to control and optimize your site's banners pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9236</guid>
    <pubDate>Wed, 27 May 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9236</strong></p>
  <p>The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the cmac_campaigns_action function. This makes it possible for unauthenticated attackers to permanently delete arbitrary advertising campaigns, including t…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9582 – A security flaw has been discovered in SourceCodester CET Automated Grading Syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9582</guid>
    <pubDate>Tue, 26 May 2026 21:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9582</strong></p>
  <p>A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35220 – Lack of CSRF token validation lead to a CSRF attack vector in the admin activati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35220</guid>
    <pubDate>Tue, 26 May 2026 17:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35220</strong></p>
  <p>Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46620 – e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46620</guid>
    <pubDate>Tue, 26 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46620</strong></p>
  <p>e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem comes down to how session_handler::check() handles CSRF tokens. Instead of requiring a token on every state-changing request, it only validates the token if one happens to be present. If there is no token at all, the check is skipped entire…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8174 – Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8174</guid>
    <pubDate>Tue, 26 May 2026 14:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8174</strong></p>
  <p>Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF).  This issue affects Zoho Mail wordpress plugin versions before 1.6.2.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39436 – Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39436</guid>
    <pubDate>Mon, 25 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39436</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery.  This issue affects CformsII: from n/a through 15.1.3.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24554 – Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24554</guid>
    <pubDate>Mon, 25 May 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24554</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery.  This issue affects WPSubscription: from n/a through 1.9.1.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24597 – Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24597</guid>
    <pubDate>Mon, 25 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24597</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery.  This issue affects Organization chart: from n/a through 1.7.5.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24574 – Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Stat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24574</guid>
    <pubDate>Mon, 25 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24574</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery.  This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9486 – A security flaw has been discovered in SourceCodester Student Grades Management ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9486</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9486</strong></p>
  <p>A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25370 – Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25370</guid>
    <pubDate>Mon, 25 May 2026 15:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25370</strong></p>
  <p>Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious HTML forms targeting roles_function.php with parameters like rol_assign_roles, rol_approve_users, and rol_edit_user set to 1 to escalate privileges without authentication.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25363 – Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25363</guid>
    <pubDate>Mon, 25 May 2026 15:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25363</strong></p>
  <p>Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms targeting tweetdel.php with tweet IDs and automatically submit them to delete arbitrary posts from authenticated user sessions.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25354 – Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25354</guid>
    <pubDate>Sat, 23 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25354</strong></p>
  <p>Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pages. Attackers can craft HTML forms targeting the account/index endpoint with hidden fields to change passwords, email addresses, and profile details without user consent.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25343 – Smartshop 1 contains a cross-site request forgery vulnerability that allows atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25343</guid>
    <pubDate>Sat, 23 May 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25343</strong></p>
  <p>Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting editprofile.php with hidden fields for email and password parameters that execute automatically when visited by an authenticated admin user.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9303 – A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9303</guid>
    <pubDate>Sat, 23 May 2026 14:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9303</strong></p>
  <p>A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41074 – RT is an open source, enterprise-grade issue and ticket tracking system. Version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41074</guid>
    <pubDate>Fri, 22 May 2026 22:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41074</strong></p>
  <p>RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that user's behalf. This issue has been fixed in version 6.0.3.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8340 – Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8340</guid>
    <pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8340</strong></p>
  <p>Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents permission is CSRF'd into publishing an attacker-chosen previously-uploaded version (downgrade to an older version of a file, or activation of a co-editor's unpublished version). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7615 – The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7615</guid>
    <pubDate>Fri, 22 May 2026 09:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7615</strong></p>
  <p>The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on the save_widget_context_settings function. This makes it possible for unauthenticated attackers to modify widget visibility context settings stored in the WordPress options table via a forged POST request to /wp-ad…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4070 – The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4070</guid>
    <pubDate>Fri, 22 May 2026 05:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4070</strong></p>
  <p>The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing nonce validation on the alfie_manage() function which handles feed deletion via the 'delete' GET parameter. This makes it possible for unauthenticated attackers to delete arbitrary plugin feed data (from alfie_colindex, alfie_producten, alfie…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8435 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8435</guid>
    <pubDate>Thu, 21 May 2026 22:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8435</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8434 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8434</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8434</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8433 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8433</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8433</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8432 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8432</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8432</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8427 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8427</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8427</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8416 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8416</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8416</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8415 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8415</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8415</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8414 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8414</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8414</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8413 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8413</guid>
    <pubDate>Thu, 21 May 2026 22:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8413</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8412 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8412</guid>
    <pubDate>Thu, 21 May 2026 22:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8412</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at 	concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8411 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8411</guid>
    <pubDate>Thu, 21 May 2026 22:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8411</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8410 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8410</guid>
    <pubDate>Thu, 21 May 2026 22:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8410</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8409 – Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8409</guid>
    <pubDate>Thu, 21 May 2026 22:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8409</strong></p>
  <p>Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7882 – Concrete CMS  9.5.0 and below is vulnerable to unauthorized file deletion due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7882</guid>
    <pubDate>Thu, 21 May 2026 22:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7882</strong></p>
  <p>Concrete CMS  9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the DeleteFile controller. The code throws an error when the token IS valid and proceeds with file deletion when the token is invalid or missing. This effectively disables CSRF protection for the file deletion endpoint, allowing cross-site request forgery attacks against users who have…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8428 – Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.ph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8428</guid>
    <pubDate>Thu, 21 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8428</strong></p>
  <p>Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never calls $this->token->validate('do_update'). The form is rendered as a POST form, meaning the token reaches the browser, but because the controller discards it withou…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8426 – Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8426</guid>
    <pubDate>Thu, 21 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8426</strong></p>
  <p>Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for a known marketplace item ID can overwrite the package PHP on disk and force its upgrade() method to execute in a single browser navigation. This results in remote code execution as the web s…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8421 – Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_packag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8421</guid>
    <pubDate>Thu, 21 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8421</strong></p>
  <p>Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php.  An attacker who can cause an authenticated administrator to visit a crafted page,  and who has placed or caused a package to be present under DIR_PACKAGES/<handle>/, can force the installation of that package without any CSRF protection. Pac…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8417 – Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8417</guid>
    <pubDate>Thu, 21 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8417</strong></p>
  <p>Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete/controllers/single_page/dashboard/extend/update.php checks only canInstallPackages() before executing upgradeCoreData() and upgrade() on the named package's controller. Because the endpoint is a state-changing GET route with n…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8140 – Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8140</guid>
    <pubDate>Thu, 21 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8140</strong></p>
  <p>Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download() method in concrete/controllers/single_page/dashboard/extend/install.php checks only the canInstallPackages() permission before fetching a remote marketplace package and writing it to the server's DIR_PACKAGES directory. Because the endpoint is a s…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39310 – Trilium Notes is a cross-platform, hierarchical note taking application focused ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39310</guid>
    <pubDate>Wed, 20 May 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39310</strong></p>
  <p>Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron environment, it explicitly disables authentication middleware for the Clipper API, exposin…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44925 – Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44925</guid>
    <pubDate>Wed, 20 May 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44925</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11954 – Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technolog...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11954</guid>
    <pubDate>Wed, 20 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11954</strong></p>
  <p>Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery.  This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6405 – The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6405</guid>
    <pubDate>Wed, 20 May 2026 08:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6405</strong></p>
  <p>The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in versions up to and including 0.3.6. This is due to missing nonce verification on the settings page handler and insufficient output escaping in the admin_options.php template. The settings form includes no wp_nonce_field() and the h…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8610 – The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authori...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8610</guid>
    <pubDate>Wed, 20 May 2026 02:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8610</strong></p>
  <p>The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the plugin's site-wide font settings, including the typesquar…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8424 – The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8424</guid>
    <pubDate>Wed, 20 May 2026 02:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8424</strong></p>
  <p>The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'rybb_api_settings' page. This makes it possible for unauthenticated attackers to reset the plugin's stored settings by overwriting its configuration via a forged request granted they can trick a site admini…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8423 – The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8423</guid>
    <pubDate>Wed, 20 May 2026 02:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8423</strong></p>
  <p>The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation on the options page. This makes it possible for unauthenticated attackers to change the site's active theme by modifying the jbct_theme option via a forged request granted they can trick a site administrat…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8420 – The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Reques...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8420</guid>
    <pubDate>Wed, 20 May 2026 02:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8420</strong></p>
  <p>The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an actio…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8419 – The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8419</guid>
    <pubDate>Wed, 20 May 2026 02:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8419</strong></p>
  <p>The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8418 – The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8418</guid>
    <pubDate>Wed, 20 May 2026 02:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8418</strong></p>
  <p>The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the gc_crud() function which handles the delete action (action=delete) via a GET request without any wp_verify_nonce() / check_admin_referer() call. This makes it possible for unauthenticated attackers to delete arbitra…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6452 – The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6452</guid>
    <pubDate>Wed, 20 May 2026 02:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6452</strong></p>
  <p>The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the bigfishgames_syndicate_submenu() function. This makes it possible for unauthenticated attackers to reset plugin settings and update them via a forged request granted they can trick a site administrator in…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6401 – The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6401</guid>
    <pubDate>Wed, 20 May 2026 02:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6401</strong></p>
  <p>The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing nonce verification on the plugin's settings update forms handled in bottom-bar-admin.php. None of the three settings forms (main settings, sharing services, restore defaults) include a wp_nonce_field(), and the server-side processing code never calls ch…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6400 – The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6400</guid>
    <pubDate>Wed, 20 May 2026 02:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6400</strong></p>
  <p>The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is due to missing nonce verification in the options() function, which handles plugin settings updates. The form template does not include a wp_nonce_field() call, and the handler never calls check_admin_referer() or wp_verify_nonce(). This makes it…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6395 – The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6395</guid>
    <pubDate>Wed, 20 May 2026 02:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6395</strong></p>
  <p>The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of nonce verification on the settings save handler in the w2c_admin() function, combined with missing input sanitization before storage and missing output escaping when rendering the stored value. The w2c…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6391 – The Sentence To SEO (keywords, description and tags) plugin for WordPress is vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6391</guid>
    <pubDate>Wed, 20 May 2026 02:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6391</strong></p>
  <p>The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the create_admin_page() function. This makes it possible for unauthenticated attackers to inject malicious web scripts and update plugin settings via a forged request granted they ca…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8604 – In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8604</guid>
    <pubDate>Tue, 19 May 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8604</strong></p>
  <p>In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7507 – A session fixation vulnerability was found in Keycloak's login-actions endpoints...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7507</guid>
    <pubDate>Tue, 19 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7507</strong></p>
  <p>A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which processes session handles without adequate CSRF protection or cookie ownership validation—an attacker c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25337 – Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25337</guid>
    <pubDate>Sun, 17 May 2026 13:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25337</strong></p>
  <p>Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords without user consent.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25336 – jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25336</guid>
    <pubDate>Sun, 17 May 2026 13:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25336</strong></p>
  <p>jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authentication. Attackers can craft malicious HTML forms targeting endpoints , and to change user credentials, passwords, and affiliate account details when victims visit the attacker-controlled page.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25334 – Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25334</guid>
    <pubDate>Sun, 17 May 2026 13:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25334</strong></p>
  <p>Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but an attacker can use the hashtag parameter to inject an encoded payload and bypass the CSRF protection, allowing for unauthorized changes to user data. This can be exploited by tricking a user into su…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25327 – Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25327</guid>
    <pubDate>Sun, 17 May 2026 13:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25327</strong></p>
  <p>Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings when administrators visit attacker-controlled pages.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25321 – TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25321</guid>
    <pubDate>Sun, 17 May 2026 13:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25321</strong></p>
  <p>TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-controlled pages.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-47981 – Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47981</guid>
    <pubDate>Sat, 16 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-47981</strong></p>
  <p>Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript in victim browsers when the form is submitted.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47976 – TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47976</guid>
    <pubDate>Sat, 16 May 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47976</strong></p>
  <p>TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can authenticate, retrieve a CSRF token from the plugin event page, and upload malicious PHP files to the textpattern/tmp/ directory for code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-47934 – MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47934</guid>
    <pubDate>Sat, 16 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-47934</strong></p>
  <p>MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and Bio. Attackers can also exploit a cross-site request forgery vulnerability in the timeline.php profile action to change a user's cover picture by crafting malicious forms that execute when victims vis…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-37241 – bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37241</guid>
    <pubDate>Sat, 16 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-37241</strong></p>
  <p>bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new administrative accounts with arbitrary credentials without requiring explicit user consent.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37241">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
