← Back
CWE-352

9,697 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,697)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lopalopa
1Music Management System
Jun 17, 2026
Aug 26, 2024
N/A· v4
3.5 LOW· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page.
1Imagerecycle
1Imagerecycle Pdf & Image Compression
Jun 17, 2026
Aug 24, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several func...Show more
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several functions in the class/class-image-otimizer.php file. This makes it possible for unauthenticated attackers to update plugin settings along with performing other actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.Show less
1Pixeljar
1Favicon Generator
Jun 17, 2026
Aug 24, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function....Show more
The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The plugin author deleted the functionality of the plugin to patch this issue and close the plugin, we recommend seeking an alternative to this plugin. CVE-2024-7864 appears to be a duplicate of this issue.Show less
1Kjayvik
1Bus Ticket Reservation System
Jun 17, 2026
Aug 23, 2024
N/A· v4
9.4 CRITICAL· v3
N/A· v2
Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.
1Jayesh
1Hotel Management System
Jun 17, 2026
Aug 22, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.
1Hono
1Hono
Jun 17, 2026
Aug 22, 2024
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementR...Show more
Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass csrf middleware using upper-case form-like MIME type. This vulnerability is fixed in 4.5.8.Show less
1Ibm
1Sterling Connect Direct Web Services
Jun 17, 2026
Aug 22, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the web...Show more
IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Aug 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that...Show more
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Management page of the system console.Show less
1Retool
1Retool
Jun 17, 2026
Aug 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resour...Show more
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Aug 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary ac...Show more
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.Show less
1Otasync
1Ota Sync Booking Engine Widget
Jun 17, 2026
Aug 21, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.7. This is due to missing or incorrect nonce validation on the otasync_widget_...Show more
The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.7. This is due to missing or incorrect nonce validation on the otasync_widget_settings_fnc() function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.Show less
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&remove=pligg.com
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete
1Pligg
1Pligg Cms
Jun 17, 2026
Aug 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files