CVE-2026-66652
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour:
CVSS
5.4
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 2, 2026 · Last modified: Sep 2, 2026 · CWE-352
Not enough EPSS history yet.
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-847708.8 HIG—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.5hCVE-2026-847648.8 HIG—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.5hCVE-2026-847597.1 HIG—
——0Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.5hCVE-2026-814324.3 MED—
——0The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted request, provided they can trick the user into performing an action such as clicking a link.6hCVE-2026-814264.3 MED—
——0The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a logged-in vendor change the shipment status of their own orders via a crafted request.6hCVE-2026-187807.1 HIG—
——0Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery.
This issue affects Talassoft Industrial Management Software: from V.4 before V.16.20h