Total
9520 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-64791 | 1 Regularlabs.com | 1 Regular Labs Extension Manager Extension For Joomla | 2026-07-27 | 8.8 High |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions. | ||||
| CVE-2026-63684 | 1 Regularlabs.com | 3 Content Templater Extension For Joomla, Rereplacer Extension For Joomla, Snippets Extension For Joomla | 2026-07-27 | 8.8 High |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items. | ||||
| CVE-2026-66428 | 2 Jgwhite33, Wordpress | 2 Wp Google Review Slider, Wordpress | 2026-07-27 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions. | ||||
| CVE-2026-61502 | 1 Rejetto | 1 Hfs | 2026-07-27 | 4.3 Medium |
| Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to code execution - by causing a logged-in administrator's browser to navigate to a crafted URL, or without any credentials against default installations when the attack originates from the server's own machine. | ||||
| CVE-2026-58476 | 1 Dan-in-ca | 1 Sip | 2026-07-27 | 8.1 High |
| Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation or origin verification. Attackers can trigger actions such as disabling the passphrase, rebooting the device, deleting programs, or installing plugins, with the default configuration exposing these endpoints to unauthenticated users due to no required passphrase and a default credential of 'opendoor'. | ||||
| CVE-2026-15747 | 1 Sri | 1 Mojolicious | 2026-07-27 | 9.1 Critical |
| Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. An attacker able to query it can recover the token and pass csrf_protect validation. | ||||
| CVE-2026-15212 | 2 Wordpress, Wpo365 | 2 Wordpress, Wpo365 | Seamless Wordpress + Microsoft Integration (wpo365 | Login) | 2026-07-27 | 8.8 High |
| The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-origin pages and forwards the attacker-supplied 'settings' payload (base64/JSON) to Options_Service::update_options(), which merges every key/value into wpo365_options without a key allowlist. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin options — including enabling the SCIM REST endpoint (enable_scim), planting an attacker-known scim_secret_token, and setting new_usr_default_role to 'administrator' — via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||
| CVE-2026-13826 | 1 Google | 1 Chrome | 2026-07-27 | 6.5 Medium |
| Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-13887 | 1 Google | 1 Chrome | 2026-07-25 | 6.5 Medium |
| Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-65757 | 1 Regularlabs.com | 1 Modules Anywhere Extension For Joomla | 2026-07-24 | 8.1 High |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. | ||||
| CVE-2026-64871 | 1 Regularlabs.com | 1 Cache Cleaner Extension For Joomla | 2026-07-24 | 5.4 Medium |
| Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission. | ||||
| CVE-2026-1673 | 2 Realmag777, Wordpress | 2 Bear – Bulk Editor And Products Manager Professional For Woocommerce By Pluginus.net, Wordpress | 2026-07-23 | 4.3 Medium |
| The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_delete_tax_term() function. This makes it possible for unauthenticated attackers to delete WooCommerce taxonomy terms (categories, tags, etc.) via a forged request granted they can trick a site administrator or shop manager into performing an action such as clicking on a link. | ||||
| CVE-2026-12409 | 2 Umarbajwa, Wordpress | 2 Landing Page Builder – Coming Soon Page, Maintenance Mode, Lead Page, Wordpress Landing Pages, Wordpress | 2026-07-23 | 4.3 Medium |
| The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. This makes it possible for unauthenticated attackers to create, update, retitle, or change the post status, slug, and type of arbitrary posts and write ULPB_DATA post meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This attack requires the victim to hold an editor-level or administrator session, as the wp_ajax_ulpb_admin_data action enforces a capability check that the forged request must satisfy by inheriting the logged-in user's session cookies. | ||||
| CVE-2026-60025 | 1 Joomdonation.com | 1 Events Booking Extension For Joomla | 2026-07-23 | 8.8 High |
| Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | ||||
| CVE-2026-9734 | 2 W3scloud, Wordpress | 2 W3sc Elementor To Zoho Crm, Wordpress | 2026-07-23 | 4.3 Medium |
| The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||
| CVE-2026-32823 | 1 Datacycle-engine | 1 Datacycle-core | 2026-07-23 | 4.3 Medium |
| dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application exposes server-side state changes through `GET` routes. Because browsers automatically send cookies on same-site top-level navigation and Rails does not apply CSRF protections to `GET`, an attacker can force a logged-in victim to modify application state by embedding a link, image, iframe, or redirect to one of these endpoints. This was confirmed on the target with a normal `Standard` account: a cross-site-style `GET` to `watch_lists/:id/add_item?thing_id=...` inserted content into a watch list with no CSRF token. Additional `GET` mutation routes exist in the codebase, including user impersonation for authorized admins and cache or translation state changes. This is patched in version 26.06.08. | ||||
| CVE-2026-64821 | 1 Thiagopena | 1 Djangosige | 2026-07-23 | 4.3 Medium |
| djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users by exploiting order-cancellation logic implemented inside HTTP GET method handlers in CancelarOrcamentoVendaView, CancelarPedidoVendaView, CancelarOrcamentoCompraView, and CancelarPedidoCompraView. Attackers can lure an authenticated victim with change_orcamentovenda or equivalent permissions to a page containing a cross-origin reference such as an img tag pointing to the cancellation endpoint, bypassing CSRF token validation entirely since Django's CsrfViewMiddleware only enforces CSRF checks on unsafe HTTP methods. | ||||
| CVE-2026-57785 | 2 Apustheme, Wordpress | 2 Apuslisting, Wordpress | 2026-07-23 | 8.8 High |
| Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. | ||||
| CVE-2026-65464 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-07-23 | 5.4 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions. | ||||
| CVE-2026-65471 | 2 Avada Studio, Wordpress | 2 Avada Core, Wordpress | 2026-07-23 | 9.6 Critical |
| Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | ||||