← Back
CWE-352

9,674 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Watchful
1Xcloner
Jun 17, 2026
Jun 27, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset t...Show more
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.Show less
11234n
1Minicms
Jun 17, 2026
Jun 24, 2022
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
1W3eden
1Download Manager
Mar 21, 2025
Jun 24, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attac...Show more
A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.Show less
1Jenkins
1Vrealize Orchestrator
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL.
1Jenkins
1Threadfix
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified URL.
1Jenkins
1Beaker Builder
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.
1Jenkins
1Jianliao Notification
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL.
1Jenkins
1Easyqa
Jun 17, 2026
Jun 23, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP server.
1Jenkins
1Convertigo Mobile Platform
Jun 17, 2026
Jun 23, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL.
1Wpjos
1Library File Manager
Nov 21, 2024
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack rem...Show more
A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely.Show less
1Global Content Blocks Project
1Global Content Blocks
Nov 21, 2024
Jun 23, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initi...Show more
A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.Show less
1Bytesforall
1Atahualpa
Nov 21, 2024
Jun 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
1Supsystic
1Popup
Nov 21, 2024
Jun 20, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remot...Show more
A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Underconstruction Project
1Underconstruction
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack
1Capa Protect Project
1Capa Protect
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable the applied...Show more
The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable the applied protection.Show less
1Wplite Project
1Wplite
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Amazon Einzeltitellinks Project
1Amazon Einzeltitellinks
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Sto...Show more
The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escapingShow less
1Inline Google Maps Project
1Inline Google Maps
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored C...Show more
The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escapingShow less
1Pdf24 Articles To Pdf Project
1Pdf24 Articles To Pdf
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Pdf24 Articles To Pdf Project
1Pdf24 Articles To Pdf
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack