REDCap prior to 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
vanderbilt redcap