← Back
CWE-352

9,666 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,666)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Jan 24, 2022
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
1Webmaster Source
1Wp125
Jun 17, 2026
Jan 24, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack
1Themeum
1Qubely
Jun 17, 2026
Jan 24, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any au...Show more
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary postsShow less
1Wpplugin
1Accept Donations With Paypal
Jun 17, 2026
Jan 24, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete...Show more
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blogShow less
1Etoilewebdesign
1Ultimate Faq
Jun 17, 2026
Jan 24, 2022
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, a...Show more
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questionsShow less
1Wp Extra File Types Project
1Wp Extra File Types
Jun 17, 2026
Jan 24, 2022
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform...Show more
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacksShow less
1Tipsandtricks Hq
1Simple Download Monitor
Jun 17, 2026
Jan 24, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerabilit...Show more
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloadsShow less
1Mblog Project
1Mblog
Jun 17, 2026
Jan 20, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
1Wangl1989
1Mysiteforme
Jun 17, 2026
Jan 19, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added
1Email Tracker Project
1Email Tracker
Jun 17, 2026
Jan 19, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions <= 5.2.6).
1Xootix
3Login/signup Popup
Side Cart WoocommerceWaitlist Woocommerce
Jun 17, 2026
Jan 18, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in t...Show more
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site. This affects versions <= 2.2 in Login/Signup Popup, versions <= 2.5.1 in Waitlist Woocommerce ( Back in stock notifier ), and versions <= 2.0 in Side Cart Woocommerce (Ajax).Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 18, 2022
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a...Show more
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.Show less
1Crisp
1Crisp
Jun 17, 2026
Jan 18, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attac...Show more
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 0.31.Show less
1Livehelperchat
1Livehelperchat
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.
1Janeczku
1Calibre Web
Jun 17, 2026
Jan 17, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
1Theeventscalendar
1Eventcalendar
Jun 17, 2026
Jan 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
1Expresstech
1Quiz And Survey Master
Jun 17, 2026
Jan 17, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially c...Show more
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.Show less
2Fedoraproject
Phoronix Media
2Fedora
Phoronix Test Suite
Jun 17, 2026
Jan 16, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Jan 14, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Jan 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)