Csrf Lite Project maintains a focused, niche library intended to provide cross-site request forgery protection, representing a narrow but critical component in web application security infrastructure. The vendor's disclosed vulnerabilities center on its primary csrf_lite product, where the durable signal reflects the complexity of implementing CSRF defenses reliably across diverse integration contexts. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Csrf Lite Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10535MEDIUM csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, instead of a time constant string | May 31, 2018 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Csrf Lite Project.
Media articles that mention a CVE ID that affects a product developed by Csrf Lite Project — matched by CVE ID, not by vendor name.