CWE-352Compound2 in KEV

Cross-Site Request Forgery (CSRF)

Stable in the CWE catalog · 5,281 CVEs mapped

5,281
CVEs mapped
2
In KEV
5.4
Median CVSS
What it is

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Recent examples
4.3cvss
CVE-2026-86182

CVE-2026-86182 - MEDIUM Severity Vulnerability

A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dm_command causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

MEDIUMno explanation yet
0%
epss
8.8cvss
CVE-2026-82712

CVE-2026-82712 - HIGH Severity Vulnerability

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

HIGHno explanation yet
0%
epss
5.2cvss
CVE-2026-53760

CVE-2026-53760 - MEDIUM Severity Vulnerability

Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because these are top-level navigations, browsers include SameSite=Lax session cookies. An attacker crafts a malicious page that, when an authenticated administrator visits it, triggers arbitrary plugin operations. The uninstall operation executes DROP TABLE SQL scripts and destroys plugin data. This issue has been patched via commit 056b1bd.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-352
Abstraction
Compound
Structure
Composite
Status
Stable
References (11)