Flarum prior to 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
flarum flarum 0.1.0