CWE-352
9,662 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,662)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logge...Show more |
1Leaflet Map Project 1Leaflet Map Jun 17, 2026 Aug 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This co...Show more |
A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users. |
Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/admin/profile/save_profile". |
1Southsoft 1Graduate Management Information System Jun 17, 2026 Aug 6, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For example: any student's photo information can be accessed through /gmis/(S([1]))/stu...Show more |
1Sola Newsletters Project 1Sola Newsletters Jun 17, 2026 Aug 5, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in vers...Show more |
1Youtube Feeder Project 1Youtube Feeder Jun 17, 2026 Aug 5, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php file which allows attackers to inject arbitrary web scripts, in versions u...Show more |
The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in the ~/news-plugin.php file which allows attackers to inject arbitrary web scripts, in versions up to...Show more |
1Bosch 7Aviotec Firmware Cpp13 FirmwareCpp14 Firmware+4 moreJun 17, 2026 Aug 5, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Aug 4, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and...Show more |
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an aut...Show more |
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenti...Show more |
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated us...Show more |
1Post Index Project 1Post Index Jun 17, 2026 Aug 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Post Index WordPress plugin is vulnerable to Cross-Site Request Forgery via the OptionsPage function found in the ~/php/settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and...Show more |
1Seo Backlinks Project 1Seo Backlinks Jun 17, 2026 Aug 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file which allows attackers to inject arbitrary web scripts, in versions up to a...Show more |
The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject...Show more |
1Ibm 1Qradar User Behavior Analytics Jun 17, 2026 Aug 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM QRadar User Behavior Analytics 4.1.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Forc...Show more |
1Wplearnmanager 1Wp Learn Manager Jun 17, 2026 Aug 2, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were...Show more |
1Migrate Users Project 1Migrate Users Jun 17, 2026 Aug 2, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF ch...Show more |
1Groupsession 3Groupsession Groupsession BycloudGroupsession ZionJun 17, 2026 Jul 30, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSes...Show more |