CWE-352
9,359 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,359)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Spreecommerce 1Spree Auth Devise Jun 17, 2026 Nov 17, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected version...Show more |
solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover...Show more |
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the foll...Show more |
1Qr Redirector Project 1Qr Redirector Jun 17, 2026 Nov 17, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscribe...Show more |
1Mousewheel Smooth Scroll Project 1Mousewheel Smooth Scroll Jun 17, 2026 Nov 17, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make a logged in admin change them via a CSRF attack |
1Simple Jwt Login Project 1Simple Jwt Login Jun 17, 2026 Nov 17, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account regist...Show more |
1Gesundheit Bewegt 1Colorful Categories Jun 17, 2026 Nov 17, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor change taxonomy colors via a CSRF attack |
1Wp Performance Score Booster Project 1Wp Performance Score Booster Jun 17, 2026 Nov 17, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. |
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-...Show more |
1Dotnetfoundation 1Piranha Cms Jun 17, 2026 Nov 16, 2021 N/A· v4 8.1 HIGH· v3 4.0 MEDIUM· v2 In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a po...Show more |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
twill is vulnerable to Cross-Site Request Forgery (CSRF) |
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add. |
1Genexis 1Platinum 4410 Firmware Jun 17, 2026 Nov 10, 2021 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router. |
Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm. |
1Airangel 5Hsmx App 1000 Firmware Hsmx App 100 FirmwareHsmx App 20000 Firmware+2 moreJun 17, 2026 Nov 10, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Airangel HSMX Gateway devices through 5.2.04 allow CSRF. |