These issues are rampant, largely due to failure to apply `@csrf_protect` decorator and lack of escaping in many templates.