Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
CWE-352
CVE-2021-40108
An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint.
CVE-2021-4015
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4005
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3993
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-39864
Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via a Wishlist Share Link. Successful exploitation could lead to unauthorized addition to customer cart by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.