← Back
CWE-352

9,359 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,359)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1E107
1E107
Jun 17, 2026
Mar 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
1Cisco
1Nx Os
Jun 17, 2026
Feb 24, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insu...Show more
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the NX-API on an affected device. An attacker could exploit this vulnerability by persuading a user of the NX-API to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. The attacker could view and modify the device configuration. Note: The NX-API feature is disabled by default.Show less
1Jenkins
1Claim
Jun 17, 2026
Feb 24, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change claims.
1Jenkins
1Configuration Slicing
Jun 17, 2026
Feb 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attackers to apply different slice configurations.
1Smartstore
1Smartstorenet
Jun 17, 2026
Feb 19, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).
1Schneider Electric
10Powerlogic Ion7400 Firmware
Powerlogic Ion7650 FirmwarePowerlogic Ion8300 Firmware+7 more
Jun 17, 2026
Feb 19, 2021
N/A· v4
4.5 MEDIUM· v3
3.5 LOW· v2
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to...Show more
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interface.Show less
2Apache
Netapp
2Myfaces
Oncommand Insight
Jun 17, 2026
Feb 19, 2021
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tok...Show more
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site request forgery (CSRF) tokens. Due to that limitation, it is possible (although difficult) for an attacker to calculate a future CSRF token value and to use that value to trick a user into executing unwanted actions on an application.Show less
1Osc
1Open Ondemand
Jun 17, 2026
Feb 19, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF.
1Racom
1M!dge Firmware
Jun 17, 2026
Feb 16, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.
1Elecom
1Ncc Ewf100rmwh2 Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the d...Show more
Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.Show less
1Elecom
1Wrc 300febk S Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the dev...Show more
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.Show less
1Elecom
1Wrc 300febk A Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the dev...Show more
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.Show less
1Logitech
1Lan W300n/rs Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device...Show more
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.Show less
1Logitech
1Lan W300n/pr5b Firmware
Jun 17, 2026
Feb 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the devi...Show more
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.Show less
1Magento
1Magento
Jun 17, 2026
Feb 11, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthoriz...Show more
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site request forgery (CSRF) vulnerability via the GraphQL API. Successful exploitation could lead to unauthorized modification of customer metadata by an unauthenticated attacker. Access to the admin console is not required for successful exploitation.Show less
1Teradici
1Cloud Access Connector
Jun 17, 2026
Feb 11, 2021
N/A· v4
6.5 MEDIUM· v3
2.6 LOW· v2
An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a...Show more
An Anti CSRF mechanism was discovered missing in the Teradici Cloud Access Connector v31 and earlier in a specific web form, which allowed an attacker with knowledge of both a machineID and user GUID to modify data if a user clicked a malicious link.Show less
1Redhat
4Jboss Fuse
KeycloakOpenshift Application Runtimes+1 more
Jun 17, 2026
Feb 11, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are...Show more
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.Show less
1Ibm
1Security Verify Information Queue
Jun 17, 2026
Feb 11, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trust...Show more
IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.Show less
1Owncloud
1Owncloud
Jun 17, 2026
Feb 9, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
1Imagely
1Nextgen Gallery
Jun 17, 2026
Feb 9, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) issue in the NextGEN Gallery plugin before 3.5.0 for WordPress allows File Upload. (It is possible to bypass CSRF protection by simply not including a nonce parameter.)