Tiny Csrf Project maintains a narrowly scoped anti-CSRF library that addresses a specific security concern in web application development. The vendor's vulnerability exposure, where observed, reflects the focused nature of a single-purpose protection mechanism rather than a broad portfolio. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tiny Csrf Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39287MEDIUM tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF tokens were transmitted in the c | Oct 7, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tiny Csrf Project.
Media articles that mention a CVE ID that affects a product developed by Tiny Csrf Project — matched by CVE ID, not by vendor name.