← Back
CWE-352

9,668 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,668)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webmin
1Webmin
Jun 17, 2026
Apr 11, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
1Webmin
1Webmin
Jun 17, 2026
Apr 11, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
1Icehrm
1Icehrm
Jun 17, 2026
Apr 8, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.
1Qdpm
1Qdpm
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Apr 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized a...Show more
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186283.Show less
1Cisco
17Ip Phone 6825 Firmware
Ip Phone 6841 FirmwareIp Phone 6851 Firmware+14 more
Jun 17, 2026
Apr 6, 2022
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSR...Show more
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform configuration changes on the affected device, resulting in a denial of service (DoS) condition.Show less
1Combodo
1Itop
Jun 17, 2026
Apr 5, 2022
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this is...Show more
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `privUITransactionFile` aren't properly checked. Versions 2.7.6 and 3.0.0 contain a patch for this issue. As a workaround, use the session implementation by adding in the iTop config file.Show less
1Formbuilder Project
1Formbuilder
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make...Show more
The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting forms, and does not sanitise as well as escape its form field values. As a result, attackers could make logged in admin update and delete arbitrary forms via a CSRF attack, and put Cross-Site Scripting payloads in them.Show less
1Yourls
1Yourls
Jun 17, 2026
Apr 3, 2022
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
1Firmware Analysis And Comparison Tool Project
1Firmware Analysis And Comparison Tool
Jun 17, 2026
Mar 30, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page.
1Pluck Cms
1Pluck
Jun 17, 2026
Mar 30, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.
1Jenkins
1Job And Node Ownership
Jun 17, 2026
Mar 29, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to restore the default ownership of a job.
1Jenkins
1Job And Node Ownership
Jun 17, 2026
Mar 29, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners and item-specific permissions of a job.
1Jenkins
1Proxmox
Jun 17, 2026
Mar 29, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified host using attacker-specified username and password (perform a connection...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins controller JVM as part of the connection test (see CVE-2022-28142), and test a rollback with attacker-specified parameters.Show less
1Jenkins
1Rocketchat Notifier
Jun 17, 2026
Mar 29, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential.
1Jenkins
1Jiratestresultreporter
Jun 17, 2026
Mar 29, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 28, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account t...Show more
Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeoverShow less
1Church Admin Project
1Church Admin
Jun 17, 2026
Mar 28, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action...Show more
The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB dataShow less
1Gtranslate
1Translate Wordpress With Gtranslate
Jun 17, 2026
Mar 28, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when...Show more
The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin cookies by making them open a malicious link or pageShow less
1Sermon Browser Project
1Sermon Browser
Jun 17, 2026
Mar 28, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary fil...Show more
The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.Show less