← Back
CWE-352

9,665 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,665)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fatcatapps
1Pixel Cat
Jun 17, 2026
Dec 13, 2021
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and per...Show more
The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacksShow less
1Storeapps
1Temporary Login Without Password
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them
1Wp Limits Project
1Wp Limits
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make a logged in admin change them, which could make the blog unstable by setting low values
1Phoeniixx
1Filter Portfolio Gallery
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could allow attackers to make a logged in admin delete arbitrary Gallery.
1Contact Form Advanced Database Project
1Contact Form Advanced Database
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, whic...Show more
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.Show less
1Wp Admin Logo Changer Project
1Wp Admin Logo Changer
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.
1Single Post Exporter Project
1Single Post Exporter
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and give access to the expor...Show more
The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and give access to the export feature to any role such as subscriber. Subscriber users would then be able to export an arbitrary post/page (such as private and password protected) via a direct URLShow less
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Dec 11, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
1Pimcore
1Pimcore
Jun 17, 2026
Dec 10, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
pimcore is vulnerable to Cross-Site Request Forgery (CSRF)
1Kimai
1Kimai 2
Jun 17, 2026
Dec 9, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
1Zzzcms
1Zzzcms
Jun 17, 2026
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
1B2evolution
1B2evolution Cms
Jun 17, 2026
Dec 6, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
1Solarwinds
1Serv U
Jun 17, 2026
Dec 6, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Serv-U server responds with valid CSRFToken when the request contains only Session.
1Tawk
1Tawk.to Live Chat
Jun 17, 2026
Dec 6, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-pri...Show more
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-privileged users (including simple subscribers) to change the 'tawkto-embed-widget-page-id' and 'tawkto-embed-widget-widget-id' parameters. Any authenticated user can thus link the vulnerable website to their own Tawk.to instance. Consequently, they will be able to monitor the vulnerable website and interact with its visitors (receive contact messages, answer, ...). They will also be able to display an arbitrary Knowledge Base. The second one will remove the live chat widget from pages.Show less
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Dec 4, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Dec 3, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the...Show more
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 202167.Show less
1Cbads
1Clickbank Affiliate Ads
Nov 21, 2024
Dec 2, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escapi...Show more
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issuesShow less
1Bookstackapp
1Bookstack
Jun 17, 2026
Dec 2, 2021
N/A· v4
6.8 MEDIUM· v3
4.0 MEDIUM· v2
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
2Debian
Gnu
2Debian Linux
Mailman
Jun 17, 2026
Dec 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.