← Back
CWE-352

9,673 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,673)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Multi Page Toolkit Project
1Multi Page Toolkit
Jun 17, 2026
Jun 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cro...Show more
The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as wellShow less
1Wp Email Project
1Wp Email
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack
1Seamless Donations Project
1Seamless Donations
Jun 17, 2026
Jun 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Webfwd
1Mail Subscribe List
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users...Show more
The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, which could allow attackers to make a logged in admin perform such action and delete arbitrary users from the subscribed listShow less
1Elefantcms
1Elefant Cms
Nov 21, 2024
Jun 20, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found in Elefant CMS 1.3.12-RC and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. Th...Show more
A vulnerability was found in Elefant CMS 1.3.12-RC and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Trendnet
1Tew 831dr Firmware
Jun 17, 2026
Jun 16, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change the username and pas...Show more
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering the existing password. A malicious user can change the username and password of the interface.Show less
1Trendnet
1Tew 831dr Firmware
Jun 17, 2026
Jun 16, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacker can change the pre-shared key of the Wi-Fi router if the interface's IP address is known.
1Jforum
1Jforum
Jul 9, 2026
Jun 16, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.
1Razormist
1Online Discussion Forum Site
Jun 17, 2026
Jun 16, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts.
1Xyzscripts
1Contact Form Manager
Nov 21, 2024
Jun 16, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery....Show more
A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Supsystic
1Photo Gallery
Jun 17, 2026
Jun 15, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows changing the plugin settings.
1Admin Management Xtended Project
1Admin Management Xtended
Jun 17, 2026
Jun 15, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.
1Ayecode
1Api Key For Google Maps
Jun 17, 2026
Jun 15, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.
1Private Messages Project
1Private Messages
Jun 17, 2026
Jun 15, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows attackers to send messages.
1Nextcode
1Image Slider By Nextcode
Jun 17, 2026
Jun 15, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress allows deleting slides.
1Nextcode
1Image Slider By Nextcode
Jun 17, 2026
Jun 15, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
1Phpgurukul
1Tourism Management System
Jun 17, 2026
Jun 14, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Tourism Management System Version: V 3.2 is affected by: Cross Site Request Forgery (CSRF).
1Employee Leaves Management System Project
1Employee Leaves Management System
Jun 17, 2026
Jun 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Employee Leaves Management System (ELMS) V 2.1 is vulnerable to Cross Site Request Forgery (CSRF) via /myprofile.php.
1Script
1Mobile Browser Color Select
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the admin_update_data() fu...Show more
The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the admin_update_data() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via forged request granted they can trick a site administrator into performing an action such as clicking on a link.Show less
1Wpmk Ajax Finder Project
1Wpmk Ajax Finder
Jun 17, 2026
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce chec...Show more
The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.1.Show less