← Back
CWE-352

9,674 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Najeebmedia
1Frontend File Manager Plugin
Jun 17, 2026
Oct 17, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf
1Miniorange
1Discord Integration
Jun 17, 2026
Oct 17, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for ex...Show more
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for exampleShow less
1Oretnom23
1Online Birth Certificate Management System
Jun 17, 2026
Oct 14, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
1Bevywise
1Mqttroute
Jun 17, 2026
Oct 13, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.
1Wayos
6Lq 04 Firmware
Lq 05 FirmwareLq 06 Firmware+3 more
Jun 17, 2026
Oct 13, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vulnerability is exploitable due to a lack...Show more
WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vulnerability is exploitable due to a lack of authentication in the component Usb_upload.htm.Show less
1Rpcms
1Rpcms
Jun 17, 2026
Oct 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add an administrator account.
1Rpcms
1Rpcms
Jun 17, 2026
Oct 13, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change the password of any account.
1Resiot
1Iot Platform And Lorawan Network Server
Jun 17, 2026
Oct 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts.
1Tenda
1Ax1803 Firmware
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
1Tenda
1Ax1803 Firmware
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.
1Tenda
1Ac1206 Firmware
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
1Tenda
1Ac1206 Firmware
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
1Getshortcodes
1Shortcodes Ultimate
Jun 17, 2026
Oct 11, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change.
1Cozmoslabs
1Profile Builder
Jun 17, 2026
Oct 11, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.
1Adguard
1Adguardhome
Jun 17, 2026
Oct 11, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious lin...Show more
In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom filtering rules functionality. An attacker can persuade an authorized user to follow a malicious link, resulting in deleting/modifying the custom filtering rules.Show less
1Siemens
10Desigo Pxm30 1 Firmware
Desigo Pxm30.e FirmwareDesigo Pxm40 1 Firmware+7 more
Jun 17, 2026
Oct 11, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions <...Show more
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). A Cross-Site Request Forgery exists in the “Import Files“ functionality of the “Operation” web application due to the missing validation of anti-CSRF tokens or other origin checks. A remote unauthenticated attacker can upload and enable permanent arbitrary JavaScript code into the device just by convincing a victim to visit a specifically crafted webpage while logged-in to the device web application.Show less
1Siemens
10Desigo Pxm30 1 Firmware
Desigo Pxm30.e FirmwareDesigo Pxm40 1 Firmware+7 more
Jun 17, 2026
Oct 11, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions <...Show more
A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). A Cross-Site Request Forgery exists in endpoints of the “Operation” web application that interpret and execute Axon language queries, due to the missing validation of anti-CSRF tokens or other origin checks. By convincing a victim to click on a malicious link or visit a specifically crafted webpage while logged-in to the device web application, a remote unauthenticated attacker can execute arbitrary Axon queries against the device.Show less
1Simplefilelist
1Simple File List
Jun 17, 2026
Oct 10, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make a logged in admin create new page and change it's content via a CSRF attack.
3Integration For Billingo & Gravity Forms Project
Integration For Szamlazz.hu & Gravity Forms ProjectWoo Billingo Plus Project
3Integration For Billingo & Gravity Forms
Integration For Szamlazz.hu & Gravity FormsWoo Billingo Plus
Jun 17, 2026
Oct 10, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF ch...Show more
The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before 1.0.4, Integration for Szamlazz.hu & Gravity Forms WordPress plugin before 1.2.7 are lacking CSRF checks in various AJAX actions, which could allow attackers to make logged in Shop Managers and above perform unwanted actions, such as deactivate the plugin's licenseShow less
1Brainvire
1Disable User Login
Jun 17, 2026
Oct 10, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.