← Back
CWE-352

9,674 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jizhicms
1Jizhicms
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
1Eyoucms
1Eyoucms
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add.
1Xunruicms
1Xunruicms
Jun 17, 2026
Aug 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
1Iptime
3Nas1dual Firmware
Nas2dual FirmwareNas4dual Firmware
Jun 17, 2026
Aug 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the roo...Show more
This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.Show less
1Dwbooster
1Calendar Event Multi View
Jun 17, 2026
Aug 16, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fiel...Show more
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.Show less
1Airspan
1Airvelocity 1500 Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
1Eyeofnetwork
1Eyes Of Network Web
Jun 17, 2026
Aug 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authentic...Show more
Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of adequate protections. An attacker can, for instance, delete the admin user by directing an authenticated user to the URL https://<target-address>/module/admin_user/index.php?DataTables_Table_0_length=10&user_selected%5B%5D=1&user_mgt_list=delete_user&action=submit by means of a crafted link.Show less
1E Unlocked Student Result Project
1E Unlocked Student Result
Jun 17, 2026
Aug 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via...Show more
The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School logo, which could allow attackers to make a logged in admin upload arbitrary files, such as PHP via a CSRF attackShow less
1Codeigniter
2Codeigniter
Shield
Jun 17, 2026
Aug 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codei...Show more
Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/libraries/security.html) mechanism with CodeIgniter Shield. For this attack to succeed, the attacker must have direct (or indirect, e.g., XSS) control over a subdomain site (e.g., `https://a.example.com/`) of the target site (e.g., `http://example.com/`). Upgrade to **CodeIgniter v4.2.3 or later** and **Shield v1.0.0-beta.2 or later**. As a workaround: set `Config\Security::$csrfProtection` to `'session,'`remove old session data right after login (immediately after ID and password match) and regenerate CSRF token right after login (immediately after ID and password match)Show less
1Zimbra
1Collaboration
Jun 17, 2026
Aug 12, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attac...Show more
An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the application that appears to be intended. The CSRF token is omitted from the request, but the request still succeeds.Show less
1Easy Username Updater Project
1Easy Username Updater
Jun 17, 2026
Aug 8, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Easy Username Updater WordPress plugin before 1.0.5 does not implement CSRF checks, which could allow attackers to make a logged in admin change any user's username includes the admin
1Mailerlite
1Mailerlite Signup Forms
Jun 17, 2026
Aug 5, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
1Starfish
1Rich Review
Jun 17, 2026
Aug 5, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an attacker to delete reviews.
1Thoughtbot
1Administrate
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
1Apache
1Jspwiki
Jun 17, 2026
Aug 4, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of thi...Show more
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also be used to modify the email associated with the attacked account, and then a reset password request from the login page.Show less
1Apache
1Jspwiki
Jun 17, 2026
Aug 4, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a...Show more
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.Show less
1Yuba
1U5cms
Jun 17, 2026
Aug 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vulnerability allows attackers to execute arbitrary code.
1Progress
1Ipswitch Ws Ftp Server
Jun 17, 2026
Aug 2, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to mitigate the risk of cross-site request forgery (CSRF) attacks.
1Ibm
1Cics Tx
Jun 17, 2026
Aug 1, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 229331.
1Givewp
1Givewp
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web s...Show more
The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exporting parameters such as dates, which could allow attackers to make a logged in admin DoS the web server via a CSRF attack as the plugin will try to retrieve data from the database many times which leads to overwhelm the target's CPU.Show less