← Back
CWE-352

9,674 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trueconf
2Server
Trueconf Server
Aug 20, 2026
Jun 29, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can...Show more
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Marvalglobal
1Marval Msm
Jun 17, 2026
Jun 28, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending the user a malicious form.
1Jorani
1Jorani
Jun 17, 2026
Jun 28, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.
1Mycss Project
1Mycss
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Clean Contact Project
1Clean Contact
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due...Show more
The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as wellShow less
1Add Post Url Project
1Add Post Url
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-S...Show more
The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escapingShow less
1Cimy Header Image Rotator Project
1Cimy Header Image Rotator
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Rotating Posts Project
1Rotating Posts
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Tiny Contact Form Project
1Tiny Contact Form
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Wp Post Styling Project
1Wp Post Styling
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP Post Styling WordPress plugin before 1.3.1 does not have CSRF checks in various actions, which could allow attackers to make a logged in admin delete plugin's data, update the settings, add new entries and more vi...Show more
The WP Post Styling WordPress plugin before 1.3.1 does not have CSRF checks in various actions, which could allow attackers to make a logged in admin delete plugin's data, update the settings, add new entries and more via CSRF attacksShow less
1Wp Sentry Project
1Wp Sentry
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site S...Show more
The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as wellShow less
1Mailpress Project
1Mailpress
Jun 17, 2026
Jun 27, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks
1Openbook Book Data Project
1Openbook Book Data
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored C...Show more
The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as wellShow less
1Supsystic
1Social Share Buttons
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin...Show more
The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.Show less
1Zatzlabs
1My Private Site
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Wpexperts
1New User Approve
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided r...Show more
The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding invitation codes, which could allow attackers to add invitation codes (for bypassing the provided restrictions) and to change plugin settings by tricking admin users into visiting specially crafted websites.Show less
1Html2wp Project
1Html2wp
Jun 17, 2026
Jun 27, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on...Show more
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote serverShow less
1Html2wp Project
1Html2wp
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them
1Html2wp Project
1Html2wp
Jun 17, 2026
Jun 27, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
1Miniorange
1Google Authenticator
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform...Show more
The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not sanitise as well as escape them, allowing attackers to make a logged in admin change them and perform Cross-Site Scripting attacksShow less