CWE-352
9,665 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,665)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and per...Show more |
1Storeapps 1Temporary Login Without Password Jun 17, 2026 Dec 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them |
1Wp Limits Project 1Wp Limits Jun 17, 2026 Dec 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make a logged in admin change them, which could make the blog unstable by setting low values |
1Phoeniixx 1Filter Portfolio Gallery Jun 17, 2026 Dec 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery. |
1Contact Form Advanced Database Project 1Contact Form Advanced Database Jun 17, 2026 Dec 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, whic...Show more |
1Wp Admin Logo Changer Project 1Wp Admin Logo Changer Jun 17, 2026 Dec 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack. |
1Single Post Exporter Project 1Single Post Exporter Jun 17, 2026 Dec 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and give access to the expor...Show more |
1Yetiforce 1Yetiforce Customer Relationship Management Jun 17, 2026 Dec 11, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) |
pimcore is vulnerable to Cross-Site Request Forgery (CSRF) |
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php. |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Dec 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges. |
Serv-U server responds with valid CSRFToken when the request contains only Session. |
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-pri...Show more |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the...Show more |
1Cbads 1Clickbank Affiliate Ads Nov 21, 2024 Dec 2, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escapi...Show more |
bookstack is vulnerable to Cross-Site Request Forgery (CSRF) |
2Debian Gnu2Debian Linux MailmanJun 17, 2026 Dec 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes. |