CWE-352
9,665 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,665)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phpgurukul 1Hostel Management System Jun 17, 2026 Dec 1, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover. |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
1Elecom 14Edwrc 2533gst2 Firmware Wrc 1167gst2 FirmwareWrc 1167gst2a Firmware+11 moreJun 17, 2026 Dec 1, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 a...Show more |
1Browser And Operating System Finder Project 1Browser And Operating System Finder Jun 17, 2026 Dec 1, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vecto...Show more |
The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary...Show more |
1Contact Form With Captcha Project 1Contact Form With Captcha Jun 17, 2026 Nov 29, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers...Show more |
1Stylishcostcalculator 1Stylish Cost Calculator Jun 17, 2026 Nov 29, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as...Show more |
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack...Show more |
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to...Show more |
1Delitestudio 1Push Notifications For Wordpress Jun 17, 2026 Nov 24, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operat...Show more |
1Xml Sitemaps 1Unlimited Sitemap Generator Jun 17, 2026 Nov 24, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specia...Show more |
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially crafted web page. |
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are alr...Show more |
The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack |
1Imagestowebp Project 1Images To Webp Jun 17, 2026 Nov 23, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrar...Show more |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF...Show more |
We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later |
1Oroinc 1Client Relationship Management Jun 17, 2026 Nov 19, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forger...Show more |