CWE-352
9,697 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,697)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF). |
A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The c...Show more |
Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Account and Deactivate functions. |
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient req...Show more |
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient req...Show more |
The Login with phone number plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.6. This is due to missing nonce validation on the 'lwp_update_password_action' function....Show more |
1Contact Manager App Project 1Contact Manager App Jun 17, 2026 Sep 10, 2023 N/A· v4 8.8 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file update.php. The manipulation leads to cross-site req...Show more |
1Contact Manager App Project 1Contact Manager App Jun 17, 2026 Sep 10, 2023 N/A· v4 8.8 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation leads to cross-si...Show more |
1Take Note App Project 1Take Note App Jun 17, 2026 Sep 9, 2023 N/A· v4 8.8 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been found in SourceCodester Take-Note App 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated...Show more |
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). |
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names fr...Show more |
A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers to clear the SQS queue. |
A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disabled modules. |
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism. |
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the...Show more |
StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)
|
1Selinc 1Sel 5037 Sel Grid Configurator Jun 17, 2026 Aug 31, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to embed instructions that could be executed by an authorized device op...Show more |
1Rednao 1Woocommerce Pdf Invoice Builder Jun 17, 2026 Aug 31, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the SaveCustomField function in versions up to, and including, 1.2.90. This makes it possible...Show more |
The Waiting: One-click countdowns plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.2. This is due to missing or incorrect nonce validation on its AJAX actions. This m...Show more |
1Rednao 1Woocommerce Pdf Invoice Builder Jun 17, 2026 Aug 31, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.90. This is due to missing or incorrect nonce validation on the Save function. Th...Show more |