Threats Tagged 'cwe-352'
View all threats tagged with 'cwe-352'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-352'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-53663: CWE-352: Cross-Site Request Forgery (CSRF) in remix-run react-routerCVE-2026-53663 0 React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. This vulnerability is fixed in 7.15.1. Join the discussion | CVE Database V5 | 06/22/2026, 17:39:29 UTC Added: 06/22/2026, 19:09:21 UTC |
CVE-2026-7859: CWE-862 Missing Authorization in MotorsCVE-2026-7859 0 The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices. Join the discussion | CVE Database V5 | 06/22/2026, 06:00:02 UTC Added: 06/22/2026, 06:09:14 UTC |
CVE-2026-49871: CWE-352 Cross-Site Request Forgery (CSRF) in Apache Software Foundation Apache APISIXCVE-2026-49871 0 Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity. Actions the victim takes upstream are then attributed to attackers identity. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. Join the discussion | CVE Database V5 | 06/19/2026, 13:18:36 UTC Added: 06/19/2026, 14:05:57 UTC |
CVE-2026-11775: CWE-352 Cross-Site Request Forgery (CSRF) in adamsilverstein User Admin SimplifierCVE-2026-11775 0 The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the useradminsimplifier_options_page function. This makes it possible for unauthenticated attackers to reset and permanently delete any user's stored menu and admin-bar configuration via a forged request that triggers uas_save_admin_options() and overwrites the useradminsimplifier_options database entry via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Join the discussion | CVE Database V5 | 06/19/2026, 02:29:39 UTC Added: 06/19/2026, 03:05:07 UTC |
CVE-2026-56024: CWE-352 Cross-Site Request Forgery (CSRF) in Saad Iqbal WP EasyPayCVE-2026-56024 0 Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0. Join the discussion | CVE Database V5 | 06/18/2026, 15:27:28 UTC Added: 06/18/2026, 16:36:21 UTC |
CVE-2026-54220: CWE-352 Cross-Site Request Forgery (CSRF) in UBB Systems UBB.threadsCVE-2026-54220 0 uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions. Join the discussion | CVE Database V5 | 06/18/2026, 12:56:18 UTC Added: 06/18/2026, 13:05:26 UTC |
CVE-2026-11784: CWE-352 Cross-Site Request Forgery (CSRF) in optimole Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image OptimizationCVE-2026-11784 0 The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due to missing or incorrect nonce validation on the replace_file function. This makes it possible for unauthenticated attackers to overwrite existing media attachments with attacker-supplied file content by supplying a forged multipart POST request targeting any attachment the victim has edit_post capability over via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The forged request requires a victim with at least Author-level privileges, as the handler enforces a current_user_can('edit_post', $id) check; tricking an Author-level or higher user into clicking a crafted link is sufficient to trigger the overwrite against attachments that user can edit. Join the discussion | CVE Database V5 | 06/18/2026, 05:34:25 UTC Added: 06/18/2026, 05:51:20 UTC |
CVE-2024-35648: CWE-352 Cross-Site request forgery (CSRF) in Andy Moyle Emergency Password ResetCVE-2024-35648 0 Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0. Join the discussion | CVE Database V5 | 06/17/2026, 12:03:47 UTC Added: 06/17/2026, 12:46:15 UTC |
CVE-2026-22342: CWE-352 Cross-Site Request Forgery (CSRF) in PremiumPress Limited. WordPress Dating ThemeCVE-2026-22342 0 Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions. Join the discussion | CVE Database V5 | 06/17/2026, 09:50:37 UTC Added: 06/17/2026, 11:08:44 UTC |
CVE-2024-34810: CWE-352 Cross-Site request forgery (CSRF) in Extend Themes Skyline WPCVE-2024-34810 0 Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10. Join the discussion | CVE Database V5 | 06/17/2026, 10:25:31 UTC Added: 06/17/2026, 11:08:33 UTC |
Showing 1 to 10 of 59 results