Golf Project maintains a narrowly scoped golf application with a durable vulnerability signal centered on cross-site request forgery (CSRF) weaknesses, a class affecting state-changing operations in web-facing services. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Golf Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-15005HIGH CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with | Dec 27, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Golf Project.
Media articles that mention a CVE ID that affects a product developed by Golf Project — matched by CVE ID, not by vendor name.