CWE-352
9,660 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,660)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibi 1Webfocus Business Intelligence Jun 17, 2026 Jun 22, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user...Show more |
WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with resultant stored cross-site scripting (XSS) via includes/admin/importers/class-wc-product-csv-importer...Show more |
1Mattermost 1Mattermost Server Nov 21, 2024 Jun 19, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF. |
1Mattermost 1Mattermost Server Nov 21, 2024 Jun 19, 2020 N/A· v4 8.8 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jun 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. |
1Mattermost 1Mattermost Server Jun 17, 2026 Jun 19, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF. |
1Mattermost 1Mattermost Server Jun 17, 2026 Jun 19, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur via a crafted web site for account takeover attacks. |
1Netgear 12Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+9 moreJun 17, 2026 Jun 18, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Certain NETGEAR devices are affected by CSRF. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK842 before 3.2.15.25, RBR840 bef...Show more |
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Jun 16, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-to...Show more |
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. |
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content i...Show more |
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request. |
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. |
1Castel 1Nextgen Dvr Firmware Jun 17, 2026 Jun 4, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified...Show more |
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF. |
Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin. |
1Jenkins 1Self Organizing Swarm Modules Jun 17, 2026 Jun 3, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove agent labels. |
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF. |
Lexiglot through 2014-11-20 allows CSRF. |
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability. |