← Back
CWE-352

9,660 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,660)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Castlerock
1Snmpc Online
Jun 17, 2026
Apr 9, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. There is pervasive CSRF.
1Plathome
2Easyblocks Ipv6 Enterprise Firmware
Easyblocks Ipv6 Firmware
Jun 17, 2026
Apr 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vecto...Show more
Cross-site request forgery (CSRF) vulnerability in EasyBlocks IPv6 Ver. 2.0.1 and earlier and Enterprise Ver. 2.0.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.Show less
1Primekey
1Ejbca
Jun 17, 2026
Apr 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.
1Auth0
1Wp Auth0
Jun 17, 2026
Apr 1, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
1Ibm
1Tivoli Netcool/impact
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts....Show more
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175411.Show less
1Ibm
1Tivoli Netcool/impact
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts....Show more
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 175410.Show less
1Lenovo
1Solution Center
Nov 21, 2024
Mar 27, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that coul...Show more
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow cross-site request forgery.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 25, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
1Zend
1Zendto
Jun 17, 2026
Mar 24, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
1Honeywell
1Win Pak
Jun 17, 2026
Mar 24, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.
2Linuxfoundation
Pivotal
2Harbor
Vmware Harbor Registry
Jun 17, 2026
Mar 20, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
1Netsas
1Enigma Network Management Solution
Jun 17, 2026
Mar 19, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or a...Show more
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to trick a victim into submitting a malicious manage_files.cgi request. This can be triggered via XSS or an IFRAME tag included within the site.Show less
1Canon
1Oce Colorwave 500 Firmware
Jun 17, 2026
Mar 19, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative...Show more
The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.Show less
1Solarwinds
1Serv U Managed File Transfer
Jun 17, 2026
Mar 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.
1Ibm
1Tivoli Netcool/omnibus
Jun 17, 2026
Mar 18, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 17...Show more
IBM Tivoli Netcool/OMNIbus 8.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174910.Show less
1Intelliants
1Subrion
Nov 21, 2024
Mar 17, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Subrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.
1Zohocorp
1Manageengine Password Manager Pro
Jun 17, 2026
Mar 16, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
1Nagios
1Nagios
Jun 17, 2026
Mar 16, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Nagios Log Server 2.1.3 has CSRF.
1Joomla
1Joomla
Jun 17, 2026
Mar 16, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.16. Missing token checks in the image actions of com_templates lead to CSRF.
1Onthegosystems
1Sitepress Multilingual Cms
Jun 17, 2026
Mar 14, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverag...Show more
The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.Show less