← Back
CWE-352

9,673 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,673)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Byonepress
1Social Locker
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Email Users Project
1Email Users
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification...Show more
The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary usersShow less
1Hc Custom Wp Admin Url Project
1Hc Custom Wp Admin Url
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to...Show more
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URLShow less
1Enqueue Anything Project
1Enqueue Anything
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low priv...Show more
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low privilege users such as subscriber could delete arbitrary assets, as well as put arbitrary posts in the trash.Show less
1Vendavo
1Pricepoint
Nov 21, 2024
Jun 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remote...Show more
A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.7.0.0 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Easy Blog Project
1Easy Blog
Jun 17, 2026
Jun 13, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a ca...Show more
Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a category via a specially crafted page.Show less
1Ibm
1Spectrum Copy Data Management
Jun 17, 2026
Jun 10, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website t...Show more
IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887.Show less
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Jun 10, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.
1Solar Log
8Solar Log 1000 Firmware
Solar Log 1000 Pm+ FirmwareSolar Log 1200 Firmware+5 more
Nov 21, 2024
Jun 9, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown functionality. The manipulation leads to cross site request forgery. The...Show more
A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown functionality. The manipulation leads to cross site request forgery. The attack may be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Chshcms
1Cscms
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.
1Theaccessgroup
1Corehr Core Portal
Jun 17, 2026
Jun 9, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site request forgery. It is possible to launch the att...Show more
A vulnerability was found in CoreHR Core Portal up to 27.0.7. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. Upgrading to version 27.0.8 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Livesync Project
1Livesync
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
1Gti
1Throws Spam Away
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack
1Tipsandtricks Hq
1Wp Simple Adsense Insertion
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via...Show more
The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.Show less
1Deliciousbrains
1Database Backup
Jun 17, 2026
Jun 8, 2022
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. T...Show more
The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backup settings, which could allow an attacker to make a logged in admin change them via a CSRF attack. This could lead to cases where attackers can send backup notification emails to themselves, which contain more details. Or disable the automatic backup scheduleShow less
1Files Download Delay Project
1Files Download Delay
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.
12code
1Ask Me
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker to trick logged in users to perform various actions on their behalf on the site.
12code
1Discy
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings back to defaults.
12code
1Discy
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods via a CSRF attack
1Easyiicms
1Easyiicms
Jun 17, 2026
Jun 7, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in easyii CMS. It has been classified as problematic. Affected is an unknown function of the file /admin/sign/out. The manipulation leads to cross site request forgery. It is possible to launch...Show more
A vulnerability was found in easyii CMS. It has been classified as problematic. Affected is an unknown function of the file /admin/sign/out. The manipulation leads to cross site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less