CWE-352
9,662 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,662)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Softwaremill 1Akka Http Session Jun 17, 2026 Jan 20, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package com.softwaremill.akka-http-session:core_2.11; the package com.softwaremill.akka-http-session:core_2.1...Show more |
Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSRF token in the cookie, it compares the CSRF token in the cookie against...Show more |
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. |
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter. |
1Bosch 2Praesensa Firmware Praesideo FirmwareJun 17, 2026 Jan 14, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions...Show more |
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim. |
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account). |
1Sean Barton 1Elementor Contact Form Db Jun 17, 2026 Jan 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages. |
1Flask Security Too Project 1Flask Security Too Jun 17, 2026 Jan 11, 2021 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. In Fl...Show more |
Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter. |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1) approve the mass of the user's comments...Show more |
1Quest 1Policy Authority For Unified Communications Jun 17, 2026 Jan 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafted link to the submitUser.jsp file. NOTE: This vulnerability only affect...Show more |
1Totalonlinesolutions 1Advanced Webhost Billing System Jun 17, 2026 Jan 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Advanced Webhost Billing System 3.7.0 is affected by Cross Site Request Forgery (CSRF) attacks that can delete a contact from the My Additional Contact page. |
The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. |
1Mcafee 1Network Security Management Jun 17, 2026 Jan 5, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via...Show more |
1Ibm 1Curam Social Program Management Jun 17, 2026 Jan 4, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts...Show more |
IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191391. |
MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI. |
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.153 for WordPress. It allows CSRF (via almost any endpoint). |
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. The pagelayer_settings_page function is vulnerable to CSRF, which can lead to XSS. |