← Back
CWE-352

9,673 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,673)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Smartptt
1Scada Server
Jun 17, 2026
Apr 29, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
1Mediawiki
1Mediawiki
Jun 17, 2026
Apr 29, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF.
1Mediawiki
1Mediawiki
Jun 17, 2026
Apr 29, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration. The attacker must trigger a POST reques...Show more
The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration. The attacker must trigger a POST request to Special:PrivateDomains.Show less
1Northern.tech
1Mender
Jun 17, 2026
Apr 28, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.
1Hermit Project
1Hermit
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title parameter.
1Hermit Project
1Hermit
Jun 17, 2026
Apr 28, 2022
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete a source, create source.
1Mahara
1Mahara
Jun 17, 2026
Apr 28, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
1Footer Text Project
1Footer Text
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.
1Shopware
1Shopware
Jun 17, 2026
Apr 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not...Show more
Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.Show less
1Tenda
1Ax12 Firmware
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.
1Tenda
1Ax12 Firmware
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.
1Wpexperts
1Mycred
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address pre...Show more
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blogShow less
1Caseproof
1Thirstyaffiliates Affiliate Link Manager
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external UR...Show more
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate link. Further the plugin lacks csrf checks, allowing an attacker to trick a logged in user to perform the action by crafting a special request.Show less
1Caseproof
1Thirstyaffiliates Affiliate Link Manager
Jun 17, 2026
Apr 25, 2022
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to creat...Show more
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to redirect users to an arbitrary websiteShow less
1Wpexperts
1Mycred
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycre...Show more
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts.Show less
1Designwall
1Dw Question & Answer
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a qu...Show more
The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, allowing attackers to make logged in users perform unwanted actions, such as update a comment or a question status.Show less
1Mingsoft
1Mcms
Jun 17, 2026
Apr 22, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Apr 22, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM...Show more
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.Show less
1Uffizio
1Gps Tracker
Jun 17, 2026
Apr 22, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.
1Cisco
1Unified Communications Manager
Jun 17, 2026
Apr 21, 2022
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote atta...Show more
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.Show less