Description Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk. Remediation References CVE-2022-2986 Related Vulnerabilities Magento Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-34254) WordPress Plugin SG Optimizer Multiple Vulnerabilities (3.3.5) MySQL CVE-2022-21444 Vulnerability (CVE-2022-21444) MySQL CVE-2022-21484 Vulnerability (CVE-2022-21484) WebLogic Missing Authentication for Critical Function Vulnerability (CVE-2025-30762) Severity High Classification CVE-2022-2986 CWE-352 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities