← Back
CWE-352

9,665 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,665)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Phoronix Media
2Fedora
Phoronix Test Suite
Jun 17, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
2Fedoraproject
Phoronix Media
2Fedora
Phoronix Test Suite
Jun 17, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
1Jenkins
1Batch Task
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve logs, build or delete a batch task.
1Jenkins
1Publish Over Ssh
Jun 17, 2026
Jan 12, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
1Jenkins
1Bitbucket Branch Source
Jun 17, 2026
Jan 12, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
2Jenkins
Oracle
2Communications Cloud Native Core Automated Test Suite
Mailer
Jun 17, 2026
Jan 12, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
2Jenkins
Oracle
2Communications Cloud Native Core Automated Test Suite
Jenkins
Jun 17, 2026
Jan 12, 2022
N/A· v4
4.3 MEDIUM· v3
2.6 LOW· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
1Salesagility
1Suitecrm
Jun 17, 2026
Jan 12, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
1Siemens
1Comos
Jun 17, 2026
Jan 11, 2022
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web c...Show more
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS uses a flawed implementation of CSRF prevention. An attacker could exploit this vulnerability to perform cross-site request forgery attacks.Show less
1Wow Company
1Wp Coder
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
1Wow Company
1Button Generator
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
1Wow Company
1Modal Window
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
5.1 MEDIUM· v2
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
1Publishpress
1Capabilities
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook,...Show more
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.
1Ultimaker
3Ultimaker 3 Firmware
Ultimaker S3 FirmwareUltimaker S5 Firmware
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver hosts APIs vulnerable to CSRF. They do not verify incoming requests.
1Vehicle Service Management System Project
1Vehicle Service Management System
Jun 17, 2026
Jan 6, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads to Stored Cross Site Scripting Vulnerability.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigations. Additionally, pages that do make use of CSRF tokens are trivially...Show more
Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigations. Additionally, pages that do make use of CSRF tokens are trivially bypassable as the server does not appear to validate them properly (i.e. re-using an old token or finding the token thru some other method is possible).Show less
1Iball
1Wrd12en Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.
1Damicms
1Damicms
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.
1Qibosoft
1Qibosoft
Jun 17, 2026
Dec 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts.