← Back
CWE-352

9,665 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,665)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Snipeitapp
1Snipe It
Jun 17, 2026
Nov 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Jun 17, 2026
Nov 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Idreamsoft
1Icms
Jun 17, 2026
Nov 12, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
1Genexis
1Platinum 4410 Firmware
Jun 17, 2026
Nov 10, 2021
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router.
1Beeline
1Smart Box Firmware
Jun 17, 2026
Nov 10, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.
1Airangel
5Hsmx App 1000 Firmware
Hsmx App 100 FirmwareHsmx App 20000 Firmware+2 more
Jun 17, 2026
Nov 10, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Airangel HSMX Gateway devices through 5.2.04 allow CSRF.
1Microsoft
1Power Bi Report Server
Aug 19, 2026
Nov 10, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directl...Show more
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has admin privileges when the victim access one of the HTML files present in the malicious Power BI template uploaded. The security update addresses the vulnerability by helping to ensure that Power BI Report Server properly sanitize file uploads.Show less
1Wp Seo Redirect 301 Project
1Wp Seo Redirect 301
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack
1Gvectors
1Wpdiscuz
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user w...Show more
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment.Show less
1Wp Survey Plus Project
1Wp Survey Plus
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sa...Show more
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to Stored Cross-Site Scripting issuesShow less
1Wpvibes
1Redirect 404 Error Page To Homepage Or Custom Page With Logs
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attac...Show more
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attackShow less
1404 To 301 Project
1404 To 301
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a C...Show more
The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a CSRF attackShow less
1Genie Wp Favicon Project
1Genie Wp Favicon
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack
1Chameleon Css Project
1Chameleon Css
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of...Show more
The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL InjectionShow less
1Ec Cloud E Commerce System Project
1Ec Cloud E Commerce System
Jun 17, 2026
Nov 4, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.
1Cisco
2Unified Communications Manager
Unified Communications Manager Im And Presence Service
Jun 17, 2026
Nov 4, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communicatio...Show more
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user. These actions could include modifying the device configuration and deleting (but not creating) user accounts.Show less
1Ayacms Project
1Ayacms
Jun 17, 2026
Nov 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Nov 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123.Show less
1Wordplus
1Better Messages
Jun 17, 2026
Nov 1, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thr...Show more
The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread, bp_better_messages_add_user_to_thread, bp_better_messages_exclude_user_from_thread. This could allow attackers to make logged in users do unwanted actionsShow less
1Tipsandtricks Hq
1Far Future Expiry Header
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.