C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-7738.json"