← Back
CWE-352

9,662 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,662)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Skyworthdigital
1Rn510 Firmware
Jun 17, 2026
Apr 9, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as...Show more
Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS).Show less
1Skyworthdigital
1Rn510 Firmware
Jun 17, 2026
Apr 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connected but an unauthenticated user visits a URL, the SSID password and web...Show more
Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connected but an unauthenticated user visits a URL, the SSID password and web UI password may be disclosed.Show less
1Indionetworks
5Unibox U1000 Firmware
Unibox U2500 FirmwareUnibox U5000 Firmware+2 more
Jul 9, 2026
Apr 9, 2021
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?...Show more
Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which a specially crafted HTTP request may reconfigure the device.Show less
1Microfocus
1Application Automation Tools
Jun 17, 2026
Apr 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow form validati...Show more
Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects version 6.7 and earlier versions. The vulnerability could allow form validation without permission checks.Show less
1Zzcms
1Zzcms
Jun 17, 2026
Apr 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.
1Web School
1Enterprise Resource Planning
Jun 17, 2026
Apr 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. The application fails to validat...Show more
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. The application fails to validate the CSRF token for a POST request using admin privilege.Show less
1Web School
1Enterprise Resource Planning
Jun 17, 2026
Apr 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/studentleaveapplication/create. The applicat...Show more
Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a student_leave_application request through module/core/studentleaveapplication/create. The application fails to validate the CSRF token for a POST request using Guardian privilege.Show less
1Jenkins
1Promoted Builds
Jun 17, 2026
Apr 7, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.
1Daifukuya
1Kagemai
Jun 17, 2026
Apr 7, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Dmasoftlab
1Radius Manager
Jun 17, 2026
Apr 7, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
1Database Backups Project
1Database Backups
Jun 17, 2026
Apr 5, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and de...Show more
The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups.Show less
1Vm Backups Project
1Vm Backups
Jun 17, 2026
Apr 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.
1Vm Backups Project
1Vm Backups
Jun 17, 2026
Apr 5, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .
1Ninjaforms
1Ninja Forms
Jun 17, 2026
Apr 5, 2021
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request...Show more
The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attackers to craft a request to disconnect a site's OAuth connection.Show less
1Expresstech
1Responsive Menu
Jun 17, 2026
Apr 5, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaS...Show more
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.Show less
1Expresstech
1Responsive Menu
Jun 17, 2026
Apr 5, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access...Show more
In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacker could then access those files to achieve remote code execution and further infect the targeted site.Show less
1Rocklobster
1Contact Form 7
Jun 17, 2026
Apr 5, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3...Show more
Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or attachment, then the request could be sent and the CSS settings would be successfully updated to include malicious JavaScript.Show less
1Softing
1Opc Toolbox
Jun 17, 2026
Apr 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a...Show more
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Apr 2, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.
1Thoughtworks
1Gocd
Jun 17, 2026
Apr 1, 2021
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which co...Show more
In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/go/api/config/backup` endpoint. An attacker can trick a victim to click on a malicious link which could change backup configurations or execute system commands in the post_backup_script field.Show less