CWE-352
9,359 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,359)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary...Show more |
1Contact Form With Captcha Project 1Contact Form With Captcha Jun 17, 2026 Nov 29, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers...Show more |
1Stylishcostcalculator 1Stylish Cost Calculator Jun 17, 2026 Nov 29, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as...Show more |
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack...Show more |
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to...Show more |
1Delitestudio 1Push Notifications For Wordpress Jun 17, 2026 Nov 24, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operat...Show more |
1Xml Sitemaps 1Unlimited Sitemap Generator Jun 17, 2026 Nov 24, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specia...Show more |
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially crafted web page. |
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are alr...Show more |
The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack |
1Imagestowebp Project 1Images To Webp Jun 17, 2026 Nov 23, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrar...Show more |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF...Show more |
We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later |
1Oroinc 1Client Relationship Management Jun 17, 2026 Nov 19, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forger...Show more |
1Teampasswordmanager 1Team Password Manager Jun 17, 2026 Nov 19, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import. |
1Easyregistrationforms 1Easy Registration Forms Jun 17, 2026 Nov 19, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible f...Show more |
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions. |