CWE-352
9,662 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,662)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. |
A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE doesn't properly set the SameSite value, allowing a Cross-Site Request...Show more |
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. |
1Ui 2Edgemax Edgepower 24v Firmware Edgemax Edgepower 54v FirmwareJun 17, 2026 Dec 14, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution. |
1Openasset 1Digital Asset Management Jul 9, 2026 Dec 14, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user...Show more |
TikiWiki 21.2 allows templates to be edited without CSRF protection. This could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected...Show more |
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart. |
1Infolific 1Ultimate Category Excluder Jun 17, 2026 Dec 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ultimate-category-excluder plugin before 1.2 for WordPress allows ultimate-category-excluder.php CSRF. |
A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a project. |
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to execute unwanted actions on a web application in which the user is currently authenticated. An attac...Show more |
Textpattern CMS 4.6.2 allows CSRF via the prefs subsystem. |
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from t...Show more |
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. |
1Softwaremill 1Akka Http Session Jun 17, 2026 Nov 27, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before...Show more |
Cloudera Data Engineering (CDE) before 1.1 was vulnerable to a CSRF attack. |
1Fastweb 1Fastgate Gpon Fga2130fwb Firmware Jun 17, 2026 Nov 24, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Fastweb FASTGate GPON FGA2130FWB devices through 2020-05-26 allow CSRF via the router administration web panel, leading to an attacker's ability to perform administrative actions such as modifying the configuration. |
1Newsscriptphp 1News Script Php Pro Jun 17, 2026 Nov 24, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users. |
Cross-site request forgery (CSRF) vulnerability in GS108Ev3 firmware version 2.06.10 and earlier allows remote attackers to hijack the authentication of administrators and the product's settings may be changed without th...Show more |
CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5...Show more |
1Orbisius 1Child Theme Creator Jun 17, 2026 Nov 16, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file. |