CVE-2026-82468
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Att
CVSS
4.7
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 29 ago 2026 · Última mod.: 29 ago 2026 · CWE-352
Sin historial EPSS suficiente todavía.
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
- github.comhttps://github.com/jeremyevans/rodauth
- github.comhttps://github.com/jeremyevans/rodauth/commit/3e0d7ab2d49a5733d1afcaaf1062b8a8258aa57a
- github.comhttps://github.com/jeremyevans/rodauth/security/advisories/GHSA-hh2f-xw94-5p79
- www.vulncheck.comhttps://www.vulncheck.com/advisories/rodauth-before-2.47.0-csrf-protection-bypass-via-content-type
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-81733——
——0WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $_REQUEST via a GET request without enforcing a CSRF token or origin check. An attacker who lures a logged-in streamer to a malicious page can silently change the live-channel viewer-redirect settings (persisted in users.externalOptions), causing viewers to be redirected to a phishing site or shown a spoofed message.13hCVE-2026-78610—4.1%
——1WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can change that administrator's passphrase to an attacker-chosen value without the administrator's consent.1dCVE-2026-758148.8 ALT7.2%
——2The Ebyte device does not adequately verify the origin or authenticity of
requests submitted to the web management interface. An unauthenticated
remote attacker could persuade an authenticated administrator to visit a
crafted page, causing unauthorized configuration changes or a
disruption of device availability.1dCVE-2026-802106.5 MED5.7%
——2FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates the token, including gl/gl_journal.php, gl/gl_bank.php, purchasing/supplier_invoice.php, sales/customer_invoice.php, sales/customer_payments.php and admin/company_preferences.php, so those endpoints act on POST data with no origin check. An attacker who gets an authenticated user to load a page under attacker control can auto-submit a cross-origin form to any of them and have the forged journal entry, invoice, customer payment, bank transaction or company configuration change recorded under the victim's session.2dCVE-2026-812738.1 ALT7.0%
——2Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.1dCVE-2026-812718.8 ALT8.0%
——2Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.1d