← Back
CWE-352

9,697 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,697)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
12code
1Wpqa Builder
Jun 17, 2026
Jul 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
12code
1Himer
Jun 17, 2026
Jul 3, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, including those they don't have access to via a CSRF attack
12code
1Himer
Jun 17, 2026
Jul 3, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group...Show more
The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. These include declining and accepting group invitations or leaving a groupShow less
12code
1Himer
Jun 17, 2026
Jul 3, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users join private groups via a CSRF attack
1Yeken
1Snippet Shortcodes
Jun 17, 2026
Jul 3, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation when adding or editing shortcodes....Show more
The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.4. This is due to missing or incorrect nonce validation when adding or editing shortcodes. This makes it possible for unauthenticated attackers to modify shortcodes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.Show less
-
-
Jun 17, 2026
Jul 2, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectname}/skills/{skillname}/video` (and probably others) is open to a cross-site request forgery (CSRF) vu...Show more
SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectname}/skills/{skillname}/video` (and probably others) is open to a cross-site request forgery (CSRF) vulnerability. Due to the endpoint being CSRFable e.g POST request, supports a content type that can be exploited (multipart file upload), makes a state change and has no CSRF mitigations in place (samesite flag, CSRF token). It is possible to perform a CSRF attack against a logged in admin account, allowing an attacker that can target a logged in admin of Skills Service to modify the videos, captions, and text of the skill. Version 2.12.6 contains a patch for this issue. Show less
1Idccms
1Idccms
Jun 17, 2026
Jul 2, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close.
1Sitetweet Project
1Sitetweet
Jun 17, 2026
Jul 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF...Show more
The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attackShow less
1Savignano
1S Notify
Jun 17, 2026
Jul 1, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.
-
-
Jun 17, 2026
Jul 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Jun 30, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Forc...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 289234.Show less
1Varniinfotech
1Floating Social Buttons
Jun 17, 2026
Jun 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_...Show more
The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.Show less
1Stitionai
1Devika
Jun 17, 2026
Jun 28, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in the context of a...Show more
A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in the context of a victim's browser, such as deleting projects or changing application settings, without any CSRF protection implemented. Successful exploitation disrupts the integrity and availability of the application and its data.Show less
1Pribai
1Privategpt
Jun 17, 2026
Jun 27, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the applicat...Show more
A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users.Show less
1Idccms
1Idccms
Jun 17, 2026
Jun 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.
1Idccms
1Idccms
Jun 17, 2026
Jun 27, 2024
N/A· v4
3.8 LOW· v3
N/A· v2
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1.
1Idccms
1Idccms
Jun 17, 2026
Jun 27, 2024
N/A· v4
3.8 LOW· v3
N/A· v2
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.
1Idccms
1Idccms
Jun 17, 2026
Jun 27, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.
1Idccms
1Idccms
Jun 17, 2026
Jun 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.
1Idccms
1Idccms
Jun 17, 2026
Jun 27, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=del&dataType=news&dataTypeCN.