← Back
CWE-352

9,359 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,359)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Power Bi Report Server
Jun 17, 2026
Nov 10, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directl...Show more
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has admin privileges when the victim access one of the HTML files present in the malicious Power BI template uploaded. The security update addresses the vulnerability by helping to ensure that Power BI Report Server properly sanitize file uploads.Show less
1Wp Seo Redirect 301 Project
1Wp Seo Redirect 301
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack
1Gvectors
1Wpdiscuz
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user w...Show more
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.Show less
1Wp Survey Plus Project
1Wp Survey Plus
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sa...Show more
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issuesShow less
1Wpvibes
1Redirect 404 Error Page To Homepage Or Custom Page With Logs
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attac...Show more
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attackShow less
1404 To 301 Project
1404 To 301
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a C...Show more
The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a CSRF attackShow less
1Genie Wp Favicon Project
1Genie Wp Favicon
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack
1Chameleon Css Project
1Chameleon Css
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of...Show more
The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL InjectionShow less
1Ec Cloud E Commerce System Project
1Ec Cloud E Commerce System
Jun 17, 2026
Nov 4, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.
1Cisco
2Unified Communications Manager
Unified Communications Manager Im And Presence Service
Jun 17, 2026
Nov 4, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communicatio...Show more
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user. These actions could include modifying the device configuration and deleting (but not creating) user accounts.Show less
1Ayacms Project
1Ayacms
Jun 17, 2026
Nov 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Nov 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123.Show less
1Wordplus
1Better Messages
Jun 17, 2026
Nov 1, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thr...Show more
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actionsShow less
1Tipsandtricks Hq
1Far Future Expiry Header
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
1Flat Preloader Project
1Flat Preloader
Jun 17, 2026
Nov 1, 2021
N/A· v4
5.4 MEDIUM· v3
5.0 MEDIUM· v2
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them wit...Show more
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the frontend or backend depending on the payload)Show less
1Wpplugin
1Accept Donations With Paypal
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control t...Show more
The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins delete arbitrary postsShow less
1Wpplugin
1Accept Donations With Paypal
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use t...Show more
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.Show less
1Delete All Comments Easily Project
1Delete All Comments Easily
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blo...Show more
The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.Show less
1Wp Pro Quiz Project
1Wp Pro Quiz
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog
1Wp Stats Project
1Wp Stats
Nov 21, 2024
Nov 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and...Show more
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloadsShow less