CWE-352
9,662 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,662)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Aug 29, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings. |
1Zohocorp 1Manageengine Cloud Security Plus Jun 17, 2026 Aug 29, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings. |
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Aug 29, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings. |
yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames |
Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete. |
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control. |
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms. |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
1Contact Form 7 Captcha Project 1Contact Form 7 Captcha Jun 17, 2026 Aug 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the se...Show more |
1Roosty 1Diary Availability Calendar Jun 17, 2026 Aug 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL statement without proper sanitisation, validation or escaping, leading to...Show more |
1Altus 15Hadron Xtorm Hx3040 Firmware Nexto Nx3003 FirmwareNexto Nx3004 Firmware+12 moreJun 17, 2026 Aug 23, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0...Show more |
A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accounts. |
In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token. |
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn. |
1Wpeasycart 1Shopping Cart & Ecommerce Store Jun 17, 2026 Aug 19, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows atta...Show more |
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn. |
Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unsp...Show more |
Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account. |