← Back
CWE-352

9,660 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,660)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kyocera
1Ecosys M5526cdw Firmware
Jun 17, 2026
Mar 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
1Xerox
1Phaser 3320 Firmware
Jun 17, 2026
Mar 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
1Netgear
1Cg3700b Firmware
Jun 17, 2026
Mar 13, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an e...Show more
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.Show less
1Untis
1Webuntis
Jun 17, 2026
Mar 13, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.
1Fortinet
1Fortisiem
Jun 17, 2026
Mar 12, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by per...Show more
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim to follow a malicious link.Show less
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a comment, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to disapprove any comment, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to approve any comment, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/reply-ticket.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to reply to any ticket, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to close any ticket, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a category, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-categories.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a category via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article template, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article template via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a department via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a department via a crafted request.