$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-352 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-352

CWE-352 — 주요 취약점

악용이 확인된 것을 먼저 보여줍니다.

전체 목록

120건

CVE-2026-85547A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections bei…0.3%보통6.2
CVE-2026-54642CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_ca…0.3%보통5.3
CVE-2026-81090The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor va…0.3%높음7.2
CVE-2026-82380Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to…0.3%높음8.1
CVE-2026-95658MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedAct…0.3%보통6.9
CVE-2026-84077IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross…0.3%높음8.1
CVE-2026-82712Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulne…0.2%높음8.6
CVE-2026-90905Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store…0.3%높음7.2
CVE-2026-19535Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI adminis…0.2%높음8.6
CVE-2026-88061career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the caree…0.2%보통5.8
CVE-2026-84084IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross…0.3%높음8.8
CVE-2026-64947A chained CSRF bypass and unrestricted file upload vulnerability in the Plugin File Manager allows an attacker…0.3%높음7.5
CVE-2026-93531A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a…0.2%낮음2.1
CVE-2026-52777YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injectio…0.2%심각9.4
CVE-2026-52823Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/times…0.2%보통5.3
CVE-2026-94220Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An …0.2%낮음2.1
CVE-2026-87449Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a …0.2%보통4.3
CVE-2026-56662GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS.…0.2%심각9.6
CVE-2026-80355Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF)…0.2%보통5.4
CVE-2026-78083Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endp…0.2%높음7.1
CVE-2026-54510Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-…0.2%높음7.1
CVE-2026-94404MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’…0.2%높음7.1
CVE-2026-85236A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint …0.2%높음8.8
CVE-2026-100873A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb9…0.2%낮음2.1
CVE-2026-85546MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality.…0.2%높음8.6
CVE-2026-95362Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker lever…0.2%높음8.8
CVE-2026-92383A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function U…0.2%낮음2.1
CVE-2026-34189Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged G…0.2%보통5.9
CVE-2026-93456django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py,…0.2%높음8.4
CVE-2026-81920Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page…0.2%낮음2.3
CVE-2026-81897In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller di…0.2%높음7.7
CVE-2026-40857WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi co…0.2%높음8.4
CVE-2026-68532Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resu…0.2%낮음2.3
CVE-2026-81907Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries"…0.2%보통6.1
CVE-2026-86066Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-…0.2%보통5.9
CVE-2026-56732Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's …0.2%보통5.3
CVE-2026-90893MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions set…0.2%보통5.1
CVE-2026-78084Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 …0.2%보통6.9
CVE-2026-81902Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeO…0.2%높음7.1
CVE-2026-85131The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processi…0.2%보통6.5
CVE-2026-50025Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.…0.2%보통6.9
CVE-2026-61593djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance.…0.2%높음8.1
CVE-2026-93873Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing at…0.2%보통5.3
CVE-2026-93870Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attacker…0.2%보통5.3
CVE-2026-81924Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activa…0.2%낮음2.1
CVE-2026-86718WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vuln…0.2%높음7.1
CVE-2026-88872AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerabi…0.2%높음7.1
CVE-2025-15399IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnera…0.2%심각10.0
CVE-2026-91857Affected versions of MISP expose several state-changing controller actions without restricting them to POST. T…0.2%보통5.3
CVE-2026-92751CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state…0.2%높음7.2
CVE-2026-92806phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber remov…0.2%높음7.2
CVE-2026-81919Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the ar…0.2%낮음2.3
CVE-2026-68526Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controlle…0.2%보통5.3
CVE-2026-90903Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in…0.2%높음7.2
CVE-2026-90599A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. …0.2%낮음2.1
CVE-2026-61687Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to …0.2%높음7.1
CVE-2026-86307A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f6…0.2%낮음2.1
CVE-2026-82911Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus…0.2%보통5.1
CVE-2026-76856Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the …0.2%높음7.0
CVE-2026-18425Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashb…0.2%낮음2.1
CVE-2026-85289InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1…0.2%보통6.5
CVE-2026-85274InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1…0.2%보통6.5
CVE-2026-81912Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The…0.2%보통5.7
CVE-2026-91819Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF an…0.2%보통6.9
CVE-2026-86182A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of t…0.2%낮음2.1
CVE-2026-86281A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination Syste…0.2%낮음2.1
CVE-2026-41875Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft spe…0.2%보통6.9
CVE-2026-86135A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature…0.2%높음7.0
CVE-2026-49992Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site r…0.2%보통6.3
CVE-2026-90900Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in…0.2%보통5.3
CVE-2026-97648A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b…0.2%낮음2.1
CVE-2026-89148AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSo…0.2%보통5.1
CVE-2026-78081Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2S…0.2%높음7.1
CVE-2026-84432Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (…0.2%보통5.3
CVE-2026-82764Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially craft…0.1%보통5.1
CVE-2026-96551A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted…0.2%낮음2.1
CVE-2026-104448YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which …0.2%높음7.2
CVE-2026-80380IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due …0.1%높음7.1
CVE-2026-89245WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vuln…0.1%높음7.1
CVE-2026-64946A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-S…0.2%높음7.4
CVE-2026-78295Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.0.1%높음8.8
CVE-2026-63373draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callba…0.2%보통4.2
CVE-2026-53760Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endp…0.1%보통5.2
CVE-2026-100748Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.00.2%보통6.9
CVE-2026-34190Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential,…0.2%보통5.9
CVE-2026-84463Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base…0.1%보통6.3
CVE-2026-88871WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site…0.1%보통5.3
CVE-2026-67993basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forger…0.1%높음8.8
CVE-2026-88873WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vuln…0.1%높음7.1
CVE-2026-100749Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only o…0.1%보통5.1
CVE-2026-100747Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an…0.1%보통5.1
CVE-2026-96838Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blackli…0.1%높음8.8
CVE-2026-39718Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request For…0.1%높음8.8
CVE-2026-62133Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.0.1%보통5.4
CVE-2026-92410The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its s…0.1%보통4.3
CVE-2026-104059Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that…0.1%높음7.0
CVE-2026-86724AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerabi…0.1%높음7.1
CVE-2026-88870WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vuln…0.1%높음7.1
CVE-2026-96524The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API no…0.1%높음8.8
CVE-2026-104447YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that a…0.1%높음7.1
CVE-2026-9215A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leve…0.1%낮음1.8
CVE-2026-101147The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordP…0.1%높음8.8
CVE-2026-63000REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src…0.1%보통6.4
CVE-2026-92582AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/vide…0.1%높음7.1
CVE-2026-94487Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.0.1%높음8.1
CVE-2026-62062Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery…0.1%높음8.8
CVE-2026-104451YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attac…0.1%보통5.3
CVE-2026-17047IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to im…0.1%보통5.4
CVE-2026-49455Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes serv…0.1%보통6.5
CVE-2026-100712froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-trigger…0.1%높음7.1
CVE-2026-103067Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows…0.1%높음8.0
CVE-2026-101093Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attac…0.1%보통5.3
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.