CWE-352
9,359 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,359)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Power Bi Report Server Jun 17, 2026 Nov 10, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directl...Show more |
1Wp Seo Redirect 301 Project 1Wp Seo Redirect 301 Jun 17, 2026 Nov 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack |
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user w...Show more |
1Wp Survey Plus Project 1Wp Survey Plus Jun 17, 2026 Nov 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sa...Show more |
1Wpvibes 1Redirect 404 Error Page To Homepage Or Custom Page With Logs Jun 17, 2026 Nov 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attac...Show more |
1404 To 301 Project 1404 To 301 Jun 17, 2026 Nov 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a C...Show more |
1Genie Wp Favicon Project 1Genie Wp Favicon Jun 17, 2026 Nov 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack |
1Chameleon Css Project 1Chameleon Css Jun 17, 2026 Nov 8, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of...Show more |
1Ec Cloud E Commerce System Project 1Ec Cloud E Commerce System Jun 17, 2026 Nov 4, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add. |
1Cisco 2Unified Communications Manager Unified Communications Manager Im And Presence ServiceJun 17, 2026 Nov 4, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communicatio...Show more |
Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts. |
1Ibm 1Infosphere Information Server Jun 17, 2026 Nov 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more |
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thr...Show more |
1Tipsandtricks Hq 1Far Future Expiry Header Jun 17, 2026 Nov 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. |
1Flat Preloader Project 1Flat Preloader Jun 17, 2026 Nov 1, 2021 N/A· v4 5.4 MEDIUM· v3 5.0 MEDIUM· v2 The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them wit...Show more |
1Wpplugin 1Accept Donations With Paypal Jun 17, 2026 Nov 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control t...Show more |
1Wpplugin 1Accept Donations With Paypal Jun 17, 2026 Nov 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use t...Show more |
1Delete All Comments Easily Project 1Delete All Comments Easily Jun 17, 2026 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blo...Show more |
1Wp Pro Quiz Project 1Wp Pro Quiz Jun 17, 2026 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog |
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and...Show more |