← Back
CWE-352

9,665 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,665)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qibosoft
1Qibosoft
Jun 17, 2026
Dec 27, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.
1Wprssaggregator
1Wp Rss Aggregator
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice...Show more
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscriber to call it and set a malicious payload in the addon parameter.Show less
1Showdoc
1Showdoc
Jun 17, 2026
Dec 26, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
1Archivy Project
1Archivy
Jun 17, 2026
Dec 25, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
archivy is vulnerable to Cross-Site Request Forgery (CSRF)
1Opms Project
1Opms
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.
1Rockoa
1Rockoa
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
1Ciphercoin
1Contact Form 7 Database Addon
Jun 17, 2026
Dec 22, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).
1Projectworlds
1Online Shopping System
Jun 17, 2026
Dec 22, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
1Projectworlds
1Online Book Store Project In Php
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.
1Wpwax
1Directorist
Jun 17, 2026
Dec 21, 2021
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.
1Nebulab
1Solidus
Jun 17, 2026
Dec 20, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a...Show more
`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item to the user's cart without their knowledge. Versions 3.1.5, 3.0.5, and 2.11.14 contain a patch for this issue. The patch adds CSRF token verification to the "Add to cart" action. Adding forgery protection to a form that missed it can have some side effects. Other CSRF protection strategies as well as a workaround involving modifcation to config/application.rb` are available. More details on these mitigations are available in the GitHub Security Advisory.Show less
1Tarteaucitron.js Cookies Legislation & Gdpr Project
1Tarteaucitron.js Cookies Legislation & Gdpr
Jun 17, 2026
Dec 20, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitron...Show more
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass".Show less
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 18, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
1Snipeitapp
1Snipe It
Jun 17, 2026
Dec 18, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
1User Management System In Php Stored Procedure Project
1User Management System In Php Stored Procedure
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allows attackers to change the password to an arbitrary account.
1Galette
1Galette
Jun 17, 2026
Dec 16, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrad...Show more
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrade to 0.9.6 as soon as possible. There are no known workarounds for this issue.Show less
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
1Catfish Cms
1Catfish Cms
Jun 17, 2026
Dec 15, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url a...Show more
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.Show less
1Glfusion
1Glfusion
Jun 17, 2026
Dec 14, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker...Show more
glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_behavior2/blacklist.php. Using the CSRF vulnerability to trick the administrator to click, an attacker can add a blacklist.Show less
1Likebtn
1Like Button Rating
Jun 17, 2026
Dec 13, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to ge...Show more
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.Show less