Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-352'

View all threats tagged with 'cwe-352'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-352

Threats Tagged 'cwe-352'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-16262: CWE-352 Cross-Site Request Forgery (CSRF) in Estatik Real Estate PluginCVE-2026-16262
0

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.

Join the discussion
CVE-2026-28172: CWE-352 Cross-Site Request Forgery (CSRF) in Data443 Risk Mitigation, Inc. Tracking Code ManagerCVE-2026-28172
0

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

Join the discussion
CVE-2026-66686: CWE-352 Cross-Site Request Forgery (CSRF) in Vladimir Garagulya Plugins Garbage Collector (Database Cleanup)CVE-2026-66686
0

Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.

Join the discussion
CVE-2026-66681: CWE-352 Cross-Site Request Forgery (CSRF) in Jeff Farthing Theme My LoginCVE-2026-66681
0

Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.

Join the discussion
CVE-2026-28172: CWE-352 Cross-Site Request Forgery (CSRF) in Data443 Risk Mitigation, Inc. Tracking Code ManagerCVE-2026-28172
0

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

Join the discussion
CVE-2025-13394: CWE-352: Cross-Site Request Forgery (CSRF) in WSO2 WSO2 Identity ServerCVE-2025-13394
0

The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET method for these operations, and while the SameSite=Lax cookie attribute is employed for mitigation, this mechanism is bypassed as it permits cookies to be sent with cross-origin top-level navigation requests, including GET requests. This allows an attacker to trick an authenticated user's browser into unknowingly executing unintended actions. An attacker can exploit this vulnerability to perform unauthorized state-altering requests on behalf of authenticated users. This could lead to consequences such as data modification, account changes, or other actions that could result in data compromise or loss of user control over their account. However, this attack is only feasible if the Carbon console and related services are exposed to the public internet, which is not recommended according to WSO2's security guidelines.

Join the discussion
CVE-2026-14313: CWE-639 Authorization Bypass Through User-Controlled Key in PeproDev WooCommerce Receipt UploaderCVE-2026-14313
0

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce.

Join the discussion
CVE-2026-14204: CWE-352 Cross-Site Request Forgery (CSRF) in Google AuthenticatorCVE-2026-14204
0

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out of their account.

Join the discussion
CVE-2026-66885: CWE-352 Cross-Site Request Forgery (CSRF) in livebook-dev livebookCVE-2026-66885
0

Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When Livebook is configured to use Livebook Teams for identity, Livebook.ZTA.LivebookTeams.handle_request/4 in lib/livebook/zta/livebook_teams.ex handles the OAuth-style callback carrying a teams_identity marker and a code parameter. The clause exchanges that code for an access token and writes the token into the browser session without verifying any value that ties the callback to the browser session that started the login. No state or nonce is generated when the flow is initiated: Livebook.Teams.Requests.create_auth_request/1 in lib/livebook/teams/requests.ex sends an empty request body, so no per-attempt value is ever registered, and the callback clause has nothing to compare against. An attacker who holds membership in the same Livebook Teams organisation as the target instance can therefore begin the login flow themselves, retain the resulting authorization code without redeeming it, and induce a victim to open a crafted URL carrying that code. The victim's browser completes the exchange and the resulting session is bound to the attacker's identity rather than the victim's. The victim is not required to hold any particular privilege, and no credential belonging to the victim is involved. The vulnerability does not allow the attacker to authenticate as the victim. The consequence is that a user believes they are working in their own authenticated session while they are in fact operating as another identity. Work performed in that session is attributed to the attacker's account, and secrets, uploaded data, or notebook results the victim produces are exposed to the attacker rather than kept in the victim's own account. The authorization code must be redeemed within a short window after the login flow begins, which constrains the timing of the attack but not its feasibility. This issue affects livebook: from 0.15.0 before 0.18.7 and from 0.19.0 before 0.19.9.

Join the discussion
CVE-2026-7326: CWE-352: Cross-Site Request Forgery (CSRF) in Progress Software Corporation MarkLogic ServerCVE-2026-7326
0

A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.

Join the discussion

Showing 1 to 10 of 81 results

Filters:Tag: cwe-352
Page 1 of 9
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses