Vulnerabilities (CVE)

Filtered by CWE-352
Total 9269 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23736 2026-06-17 N/A 8.8 HIGH
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.
CVE-2024-23734 1 Savignano 1 S-notify 2026-06-17 N/A 5.2 MEDIUM
Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.
CVE-2024-23597 2026-06-17 N/A 4.3 MEDIUM
Cross-site request forgery (CSRF) vulnerability exists in TvRock 0.9t8a. If a logged-in user of TVRock accesses a specially crafted page, unintended operations may be performed. Note that the developer was unreachable, therefore, users should consider stop using TvRock 0.9t8a.
CVE-2024-23554 1 Hcltech 1 Bigfix Platform 2026-06-17 N/A 5.7 MEDIUM
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
CVE-2024-23515 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Cincopa Post Video Players.This issue affects Post Video Players: from n/a through 1.159.
CVE-2024-23510 1 Martynchamberlin 1 Dont Muck My Markup 2026-06-17 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Martyn Chamberlin Don't Muck My Markup.This issue affects Don't Muck My Markup: from n/a through 1.8.
CVE-2024-23319 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 3.5 LOW
Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection in Mattermost only by viewing the message.
CVE-2024-23094 1 Flusity 1 Flusity 2026-06-17 N/A 8.8 HIGH
Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_media_gallery/action/edit_addon_post.php
CVE-2024-22939 1 Sunkaifei 1 Flycms 2026-06-17 N/A 8.8 HIGH
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.
CVE-2024-22859 1 Laravel 1 Livewire 2026-06-17 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 419 status codes for legitimate client activity), not a security problem.
CVE-2024-22819 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.
CVE-2024-22818 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save
CVE-2024-22817 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte
CVE-2024-22721 1 Formtools 1 Form Tools 2026-06-17 N/A 6.3 MEDIUM
Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.
CVE-2024-22715 1 Codelyfe 1 Stupid Simple Cms 2026-06-17 N/A 8.8 HIGH
Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
CVE-2024-22699 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.
CVE-2024-22643 1 Seopanel 1 Seo Panel 2026-06-17 N/A 6.5 MEDIUM
A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.
CVE-2024-22603 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link
CVE-2024-22601 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save
CVE-2024-22593 1 Flycms Project 1 Flycms 2026-06-17 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save