CWE-352
9,673 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,673)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Deltacontrols 1Entelitouch Firmware Jun 17, 2026 Jun 2, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request. |
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. |
1Supsystic 1Social Share Buttons Jun 17, 2026 Jun 2, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress. |
Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index. |
solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16 contain a cross-site request forgery (CSRF) vulnerability. The vulnerability allows attackers to ch...Show more |
1Ibm 2Business Automation Workflow Business Process ManagerJun 17, 2026 May 31, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1...Show more |
1Bulk Page Creator Project 1Bulk Page Creator Jun 17, 2026 May 30, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF. |
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings....Show more |
1Content Mask Project 1Content Mask Jun 17, 2026 May 30, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result,...Show more |
The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugins admin page, and does not sanitise some parameters, leading to a stored Cross-Site Scripting vulne...Show more |
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed thi...Show more |
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add. |
1Simple Food Website Project 1Simple Food Website Jul 9, 2026 May 23, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account. |
Cross-Site Request Forgery (CSRF) vulnerability in KubiQ CPT base plugin <= 5.8 at WordPress allows an attacker to delete the CPT base. |
1Png To Jpg Project 1Png To Jpg Jun 17, 2026 May 20, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter &jpg_quality. |
1Disable Right Click For Wp Wordpress 1Disable Right Click For Wp Jun 17, 2026 May 20, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress. |
1Phpgurukul 1Online Banquet Booking System Jun 17, 2026 May 20, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request. |
A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server. |
1Tibco 1Businessconnect Trading Community Management Jun 17, 2026 May 18, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cro...Show more |
1Meikyo 15Poe Boot Nino Poe8m2 Firmware Pose Se10 8a7b1 FirmwareSignage Rebooter Rpc M4hsi Firmware+12 moreJun 17, 2026 May 18, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [End of Sale] all firmware versions, WATCH BOOT L-zero RPC-M4L [End of Sal...Show more |