← Back
CWE-352

9,668 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,668)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1B4after
1Osmapper
Jun 17, 2026
Mar 28, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There i...Show more
The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that the post to delete is a map one. As a result, unauthenticated user can delete arbitrary posts from the blogShow less
1Typesettercms
1Typesetter
Jul 9, 2026
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.
1Phpipam
1Phpipam
Jun 17, 2026
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.
1Anchorcms
1Anchor Cms
Jun 17, 2026
Mar 24, 2022
N/A· v4
4.5 MEDIUM· v3
3.5 LOW· v2
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.
1Passwork
1Passwork
Jun 17, 2026
Mar 23, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.
1Yooslider
1Yoo Slider
Jun 17, 2026
Mar 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into unwanted slider duplicate or delete action.
1Xiaohuanxiong Project
1Xiaohuanxiong Cms
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.
1Xiaohuanxiong Cms Project
1Xiaohuanxiong Cms
Jun 17, 2026
Mar 23, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.
1Chamilo
1Chamilo
Jun 17, 2026
Mar 21, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
1Bigantsoft
1Bigant Server
Jul 9, 2026
Mar 21, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
1Simple Membership Plugin
1Simple Membership
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack
1Tms Outsource
1Amelia
Jun 17, 2026
Mar 21, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow attackers to make a logged in admin delete arbitrary customers via a CSRF attack
1Craterapp
1Crater
Jun 17, 2026
Mar 21, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
1Miniorange
1Google Authenticator
Jun 17, 2026
Mar 21, 2022
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a r...Show more
The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options from the blog, making it unusable.Show less
1Vsourz
1Advanced Cf7 Db
Jun 17, 2026
Mar 21, 2022
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authent...Show more
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.Show less
1Snapt
1Aria
Jun 17, 2026
Mar 21, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.
1Irz
5Rl01 Firmware
Rl21 FirmwareRu21 Firmware+2 more
Jun 17, 2026
Mar 19, 2022
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat acto...Show more
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.Show less
1Jenkins
1Release Helper
Jun 17, 2026
Mar 15, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
1Jenkins
1Kubernetes Continuous Deploy
Jun 17, 2026
Mar 15, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Extended Choice Parameter
Jun 17, 2026
Mar 15, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to an attacker-specified URL.