← Back
CWE-352

9,361 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,361)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wp Edit Menu Project
1Wp Edit Menu
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow unauthenticated attackers to delete arbitrary posts/pages from the blog
1Wp Edit Menu Project
1Wp Edit Menu
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make a logged in admin delete arbitrary posts/pages from the blog via a CSRF attack
1Linkworth
1Linkworth
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logged in admin change settings via a CSRF attack.
1Inkthemes
1Ask Me
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted...Show more
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.Show less
1Thimpress
1Wp Hotel Booking
Jun 17, 2026
Aug 22, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
1Transposh
1Transposh Wordpress Translation
Jun 17, 2026
Aug 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sani...Show more
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX action, which could allow attackers to make authorised users add a translation. Given the lack of sanitisation in the tk0 parameter, this could lead to a Stored Cross-Site Scripting issue which will be executed in the context of a logged in adminShow less
1Wellcms
1Wellcms
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
1Jizhicms
1Jizhicms
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
1Eyoucms
1Eyoucms
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
1Xunruicms
1Xunruicms
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
1Iptime
3Nas1dual Firmware
Nas2dual FirmwareNas4dual Firmware
Jun 17, 2026
Aug 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the roo...Show more
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.Show less
1Dwbooster
1Calendar Event Multi View
Jun 17, 2026
Aug 16, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fiel...Show more
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.Show less
1Airspan
1Airvelocity 1500 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
1Eyeofnetwork
1Eyes Of Network Web
Jun 17, 2026
Aug 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authentic...Show more
Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authenticated user to the URL https://<target-address>/module/admin_user/index.php?DataTables_Table_0_length=10&user_selected%5B%5D=1&user_mgt_list=delete_user&action=submit by means of a crafted link.Show less
1E Unlocked Student Result Project
1E Unlocked Student Result
Jun 17, 2026
Aug 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via...Show more
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attackShow less
1Codeigniter
2Codeigniter
Shield
Jun 17, 2026
Aug 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codei...Show more
Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/libraries/security.html) mechanism with CodeIgniter Shield. For this attack to succeed, the attacker must have direct (or indirect, e.g., XSS) control over a subdomain site (e.g., `https://a.example.com/`) of the target site (e.g., `http://example.com/`). Upgrade to **CodeIgniter v4.2.3 or later** and **Shield v1.0.0-beta.2 or later**. As a workaround: set `Config\Security::$csrfProtection` to `'session,'`remove old session data right after login (immediately after ID and password match) and regenerate CSRF token right after login (immediately after ID and password match)Show less
1Zimbra
1Collaboration
Jun 17, 2026
Aug 12, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attac...Show more
An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the application that appears to be intended. The CSRF token is omitted from the request, but the request still succeeds.Show less
1Easy Username Updater Project
1Easy Username Updater
Jun 17, 2026
Aug 8, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin
1Mailerlite
1Mailerlite Signup Forms
Jun 17, 2026
Aug 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
1Starfish
1Rich Review
Jun 17, 2026
Aug 5, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews.