CWE-352
9,665 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,665)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL. |
1Wprssaggregator 1Wp Rss Aggregator Jun 17, 2026 Dec 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice...Show more |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
archivy is vulnerable to Cross-Site Request Forgery (CSRF) |
A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add. |
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account. |
1Ciphercoin 1Contact Form 7 Database Addon Jun 17, 2026 Dec 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9). |
1Projectworlds 1Online Shopping System Jun 17, 2026 Dec 22, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart. |
1Projectworlds 1Online Book Store Project In Php Jun 17, 2026 Dec 22, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book. |
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory. |
`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a...Show more |
1Tarteaucitron.js Cookies Legislation & Gdpr Project 1Tarteaucitron.js Cookies Legislation & Gdpr Jun 17, 2026 Dec 20, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitron...Show more |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Dec 18, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
1User Management System In Php Stored Procedure Project 1User Management System In Php Stored Procedure Jun 17, 2026 Dec 16, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account. |
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrad...Show more |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Dec 16, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url a...Show more |
glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker...Show more |
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to ge...Show more |