CWE-352
9,677 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,677)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. |
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. |
The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it pos...Show more |
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4. |
The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the custom_404_pro_admin_init function....Show more |
1Sewio 1Real Time Location System Studio Jun 17, 2026 Jan 18, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its monitor services. An attacker could take advantage of this vulnerability...Show more |
1Sewio 1Real Time Location System Studio Jun 17, 2026 Jan 18, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its backup services. An attacker could take advantage of this vulnerability t...Show more |
1Panasonic 5Vcc Hd2100p Firmware Vcc Hd3100p FirmwareVcc Hd3300 Firmware+2 moreJun 17, 2026 Jan 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are
vulnerable to CSRFs that can be exploited to allow an attacker to
perform changes with administrator level privileges.
|
1Ate Mahoroba 3Maho Pbx Netdevancer Firmware Maho Pbx Netdevancer Mobilegate FirmwareMaho Pbx Netdevancer Vsg FirmwareJun 17, 2026 Jan 17, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Cross-site request forgery (CSRF) vulnerability in MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office pri...Show more |
Cross-Site Request Forgery (CSRF) in MiKa's OSM – OpenStreetMap plugin <= 6.0.1 versions. |
Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
|
Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php. |
The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on its AJAX actions fu...Show more |
Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users. |
Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation. |
1Royal Elementor Addons 1Royal Elementor Addons Jun 17, 2026 Jan 10, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.59. This is due to missing nonce validation in the 'wpr_create_mega_menu_template' AJAX fu...Show more |
1Royal Elementor Addons 1Royal Elementor Addons Jun 17, 2026 Jan 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated...Show more |
1Royal Elementor Addons 1Royal Elementor Addons Jun 17, 2026 Jan 9, 2023 N/A· v4 3.1 LOW· v3 N/A· v2 The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authentic...Show more |
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST request with an arbitrary body given they clic...Show more |
1Swifty Page Manager Project 1Swifty Page Manager Jun 17, 2026 Jan 5, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Swifty Page Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on several AJAX actions handling page...Show more |