← Back
CWE-352

9,359 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,359)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Stetic
1Stetic
Jun 17, 2026
Nov 29, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary...Show more
The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.0.6.Show less
1Contact Form With Captcha Project
1Contact Form With Captcha
Jun 17, 2026
Nov 29, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers...Show more
The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.6.2.Show less
1Stylishcostcalculator
1Stylish Cost Calculator
Jun 17, 2026
Nov 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as...Show more
The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site Scripting attacks against logged in admin, as well as frontend users due to the lack of sanitisation and escaping in some parametersShow less
1Kaizencoders
1Url Shortify
Jun 17, 2026
Nov 29, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack...Show more
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.Show less
1Redash
1Redash
Jun 17, 2026
Nov 24, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to...Show more
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a Cross-Site Request Forgery (CSRF) token, not a static and easily predicted value. This vulnerability does not affect users who do not use Google Login for their instance of Redash. A patch in the `master` and `release/10.x.x` branches addresses this by replacing `Flask-Oauthlib` with `Authlib` which automatically provides and validates a CSRF token for the state variable. The new implementation stores the next URL on the user session object. As a workaround, one may disable Google Login to mitigate the vulnerability.Show less
1Delitestudio
1Push Notifications For Wordpress
Jun 17, 2026
Nov 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operat...Show more
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.Show less
1Xml Sitemaps
1Unlimited Sitemap Generator
Jun 17, 2026
Nov 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specia...Show more
Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page.Show less
1Ec Cube
1Ec Cube
Jun 17, 2026
Nov 24, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially crafted web page.
1Metagauss
1Download Plugin
Jun 17, 2026
Nov 23, 2021
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are alr...Show more
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.Show less
1Feataholic
1Maz Loader
Jun 17, 2026
Nov 23, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack
1Imagestowebp Project
1Images To Webp
Jun 17, 2026
Nov 23, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrar...Show more
The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversionShow less
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Nov 22, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF...Show more
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.Show less
1Qnap
1Qmailagent
Jun 17, 2026
Nov 20, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later
1Oroinc
1Client Relationship Management
Jun 17, 2026
Nov 19, 2021
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forger...Show more
OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and all users are advised to update their package.Show less
1Teampasswordmanager
1Team Password Manager
Jun 17, 2026
Nov 19, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.
1Easyregistrationforms
1Easy Registration Forms
Jun 17, 2026
Nov 19, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible f...Show more
The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 2.1.1.Show less
1Kimai
1Kimai 2
Jun 17, 2026
Nov 19, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
1Kimai
1Kimai 2
Jun 17, 2026
Nov 19, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
1Kimai
1Kimai 2
Jun 17, 2026
Nov 19, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
1Webfactoryltd
1Wp Reset Pro
Jun 17, 2026
Nov 18, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.