CWE-352
9,674 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vulnerability. A(n) remote unauthenticated attacker could potentially exploit this vulnerability, lead...Show more |
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For m...Show more |
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated. |
1Ibm 2Partner Engagement Manager Partner Engagement Manager On Cloud/saasJun 17, 2026 Jul 19, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that...Show more |
1Ibm 1Engineering Requirements Quality Assistant On Premises Jun 17, 2026 Jul 18, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user th...Show more |
1Freemind Wp Browser Project 1Freemind Wp Browser Jun 17, 2026 Jul 18, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing nonce protection on the FreemindOptions() function found in the ~/free...Show more |
The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1. This is due to missing nonce protection on the createDOMStructure() function found in the ~/anymin...Show more |
The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.0.27 due to failure to properly check for the existence of a nonce in the function gifeed_dup...Show more |
The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 due to failure to properly check for the existence of a nonce in the function ewic_duplicate_slider....Show more |
The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.11. This is due to missing nonce protection on the livesupporti_settings() function found i...Show more |
The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4. This is due to missing nonce protection on the dxss_admin_page() function found in the ~/dx-sh...Show more |
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This mak...Show more |
A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read files via an uploaded file such as a settings/preferences file. |
1Import Csv Files Project 1Import Csv Files Jun 17, 2026 Jul 17, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected...Show more |
1Jquery Validation For Contact Form 7 Project 1Jquery Validation For Contact Form 7 Jun 17, 2026 Jul 17, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_ro...Show more |
1Insights From Google Pagespeed Project 1Insights From Google Pagespeed Jun 17, 2026 Jul 17, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such acti...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Jul 12, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and...Show more |
1Wp Opt In Project 1Wp Opt In Jun 17, 2026 Jul 11, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails. |
1Cache Images Project 1Cache Images Jun 17, 2026 Jul 11, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack. |
1Comment License Project 1Comment License Jun 17, 2026 Jul 11, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |