CWE-352
9,665 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,665)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Flat Preloader Project 1Flat Preloader Jun 17, 2026 Nov 1, 2021 N/A· v4 5.4 MEDIUM· v3 5.0 MEDIUM· v2 The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them wit...Show more |
1Wpplugin 1Accept Donations With Paypal Jun 17, 2026 Nov 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control t...Show more |
1Wpplugin 1Accept Donations With Paypal Jun 17, 2026 Nov 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use t...Show more |
1Delete All Comments Easily Project 1Delete All Comments Easily Jun 17, 2026 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blo...Show more |
1Wp Pro Quiz Project 1Wp Pro Quiz Jun 17, 2026 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged in admin delete arbitrary quiz on the blog |
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and...Show more |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website th...Show more |
1Strategy11 1Formidable Form Builder Jun 17, 2026 Oct 25, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection b...Show more |
1Wp Debugging Project 1Wp Debugging Jun 17, 2026 Oct 25, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users. |
1Jquery Reply To Comment Project 1Jquery Reply To Comment Jun 17, 2026 Oct 25, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote String' and 'Reply String' settings before outputting them in Comments, l...Show more |
The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and was also lacking sanitisation as well as escaping before outputting it...Show more |
1Commscope 1Arris Surfboard Sb8200 Firmware Jun 17, 2026 Oct 21, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the adminis...Show more |
1Atlassian 2Jira Data Center Jira ServerJun 17, 2026 Oct 21, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF) vulnerability, following an Information Disclosure vulnerability in th...Show more |
A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without th...Show more |
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then us...Show more |
ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use this vulnerability to perform illegal authorization operations by sending a request to the user to cli...Show more |
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker...Show more |