CWE-352
9,667 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,667)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Orange Form Project 1Orange Form Jun 17, 2026 Feb 28, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page th...Show more |
1Orange Form Project 1Orange Form Jun 17, 2026 Feb 28, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated us...Show more |
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. |
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later. |
1Ec Cube 1E Mail Newsletter Management Jun 17, 2026 Feb 24, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated at...Show more |
1Zyxel 2Nbg6816 Firmware Nbg6817 FirmwareJun 17, 2026 Feb 24, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website wi...Show more |
1Spiffyplugins 1Spiffy Calendar Jun 17, 2026 Feb 21, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0). |
1Wp Buy 1Wp Content Copy Protection & No Right Click Jun 17, 2026 Feb 21, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress plugin (versions <= 3.4.4). |
The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF attack |
1Wpdevart 1Coming Soon And Maintenance Mode Jun 17, 2026 Feb 21, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed...Show more |
1Wpdevart 1Coming Soon And Maintenance Mode Jun 17, 2026 Feb 21, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber...Show more |
The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack |
Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on webs...Show more |
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. |
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF). |
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF). |
1Scratch Wiki 1Scratch Confirmaccount V3 Jun 17, 2026 Feb 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses. |
A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials. |
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response. |
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine...Show more |