CWE-352
9,360 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,360)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL. |
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF). |
1Simple Membership Plugin 1Simple Membership Jun 17, 2026 Mar 21, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack |
The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack |
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. |
1Miniorange 1Google Authenticator Jun 17, 2026 Mar 21, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a r...Show more |
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authent...Show more |
A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors. |
1Irz 5Rl01 Firmware Rl21 FirmwareRu21 Firmware+2 moreJun 17, 2026 Mar 19, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat acto...Show more |
A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials. |
1Jenkins 1Kubernetes Continuous Deploy Jun 17, 2026 Mar 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs...Show more |
1Jenkins 1Extended Choice Parameter Jun 17, 2026 Mar 15, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to an attacker-specified URL. |
1Jenkins 1Cloudbees Aws Credentials Jun 17, 2026 Mar 15, 2022 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-spe...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Mar 14, 2022 N/A· v4 2.4 LOW· v3 3.5 LOW· v2 IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could allow a page linked to from within Operations Center to rewrite it. An administrator could enter a li...Show more |
1Ibm 1Spectrum Protect Operations Center Jun 17, 2026 Mar 14, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the...Show more |
An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weakened version of CSRF, where an arbitrary token of a low-privileged user (...Show more |
2Fedoraproject Weplugins2Fedora Wp MapsJun 17, 2026 Mar 11, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3). |
1Devowl 1Wordpress Real Cookie Banner Jun 17, 2026 Mar 7, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset t...Show more |
1Icegram 1Email Subscribers & Newsletters Jun 17, 2026 Mar 7, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks...Show more |
1Fatcatapps 1Easy Pricing Tables Jun 17, 2026 Mar 7, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a logged in admin remove arbitrary posts from the blog via a CSRF attack, w...Show more |