Security tokens were introduced in 3.6.10, so it's not so odd that your searching is leading you to 3.7 versions. Here is a thread about this issue:
Implementing CSRF Protection in modifications Did you recently upgrade to 3.6.10? If so, you need to make sure that take a look at any templates you chose not to revert and make sure you add the security token into any forms in those templates.