← Back
CWE-352

9,360 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,360)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Static Page Extended Project
1Static Page Extended
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also l...Show more
Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settingsShow less
1Peter's Collaboration E Mails Project
1Peter's Collaboration E Mails
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts...Show more
The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its settings, which can be used to lower the required user level, change texts, the used email address and more.Show less
1Rb Internal Links Project
1Rb Internal Links
Jun 17, 2026
Jun 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform...Show more
The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escapingShow less
1Genki Pre Publish Reminder Project
1Genki Pre Publish Reminder
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to...Show more
The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings.Show less
1Useful Banner Manager Project
1Useful Banner Manager
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin b...Show more
The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.Show less
1Latest Tweets Widget Project
1Latest Tweets Widget
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Webriti
1Webriti Smtp Mail
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Byonepress
1Social Locker
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Email Users Project
1Email Users
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification...Show more
The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary usersShow less
1Hc Custom Wp Admin Url Project
1Hc Custom Wp Admin Url
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to...Show more
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URLShow less
1Enqueue Anything Project
1Enqueue Anything
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low priv...Show more
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low privilege users such as subscriber could delete arbitrary assets, as well as put arbitrary posts in the trash.Show less
1Vendavo
1Pricepoint
Nov 21, 2024
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remote...Show more
A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.7.0.0 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Easy Blog Project
1Easy Blog
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a ca...Show more
Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a category via a specially crafted page.Show less
1Ibm
1Spectrum Copy Data Management
Jun 17, 2026
Jun 10, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website t...Show more
IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887.Show less
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Jun 10, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.
1Solar Log
8Solar Log 1000 Firmware
Solar Log 1000 Pm+ FirmwareSolar Log 1200 Firmware+5 more
Nov 21, 2024
Jun 9, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown functionality. The manipulation leads to cross site request forgery. The...Show more
A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown functionality. The manipulation leads to cross site request forgery. The attack may be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Chshcms
1Cscms
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
1Theaccessgroup
1Corehr Core Portal
Jun 17, 2026
Jun 9, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site request forgery. It is possible to launch the att...Show more
A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. Upgrading to version 27.0.8 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Livesync Project
1Livesync
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Gti
1Throws Spam Away
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack