← Back
CWE-352

9,667 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,667)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Orange Form Project
1Orange Form
Jun 17, 2026
Feb 28, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page th...Show more
In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF protection, it is actually exploitable and could allow attackers to make a logged in admin delete arbitrary posts for exampleShow less
1Orange Form Project
1Orange Form
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated us...Show more
The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated users could allow attackers to delete arbitrary posts.The AJAX calls performing actions on posts also do not ensure that the post belong to them (or that they are allowed to perform such action on it)Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
1Apache
1Jspwiki
Jun 17, 2026
Feb 25, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.
1Ec Cube
1E Mail Newsletter Management
Jun 17, 2026
Feb 24, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated at...Show more
Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (for EC-CUBE 4 series) and ver1.0.0 to 1.0.4 (for EC-CUBE 3 series) allows a remote unauthenticated attacker to hijack the authentication of an administrator via a specially crafted page, and Mail Magazine Templates and/or transmitted history information may be deleted unintendedly.Show less
1Zyxel
2Nbg6816 Firmware
Nbg6817 Firmware
Jun 17, 2026
Feb 24, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website wi...Show more
A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.Show less
1Spiffyplugins
1Spiffy Calendar
Jun 17, 2026
Feb 21, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).
1Wp Buy
1Wp Content Copy Protection & No Right Click
Jun 17, 2026
Feb 21, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress plugin (versions <= 3.4.4).
1Wow Estore
1Float Menu
Jun 17, 2026
Feb 21, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow attackers to make a logged in admin delete them via a CSRF attack
1Wpdevart
1Coming Soon And Maintenance Mode
Jun 17, 2026
Feb 21, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed...Show more
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attackShow less
1Wpdevart
1Coming Soon And Maintenance Mode
Jun 17, 2026
Feb 21, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber...Show more
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed usersShow less
1Bologer
1Anycomment
Jun 17, 2026
Feb 21, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make logged in admin perform such actions via a CSRF attack
1Plesk
1Plesk
Jun 17, 2026
Feb 20, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on webs...Show more
Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NOTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk usersShow less
1Microweber
1Microweber
Jun 17, 2026
Feb 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
1Filecloud
1Filecloud
Jun 17, 2026
Feb 16, 2022
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
1Filecloud
1Filecloud
Jun 17, 2026
Feb 16, 2022
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
1Scratch Wiki
1Scratch Confirmaccount V3
Jun 17, 2026
Feb 15, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account request requirement bypasses.
1Jenkins
1Swamp
Jun 17, 2026
Feb 15, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.
1Jenkins
1Chef Sinatra
Jun 17, 2026
Feb 15, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
1Jenkins
1Dbcharts
Jun 17, 2026
Feb 15, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.Show less