← Back
CWE-352

9,660 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,660)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a ticket via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a news article via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/add-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new glossary term via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in admin/add-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new news article via a crafted request.
1Chadhaajay
1Phpkb
Jun 17, 2026
Mar 12, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial of service, via a crafted request.
1Sumavision
1Enhanced Multimedia Router Firmware
Jun 17, 2026
Mar 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<...Show more
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.Show less
1Phpbb
1Phpbb
Jun 17, 2026
Mar 11, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.
1Sap
1Cloud Platform Integration
Jun 17, 2026
Mar 10, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attacker...Show more
SAP Cloud Platform Integration for Data Services, version 1.0, allows user inputs to be reflected as error or warning massages. This could mislead the victim to follow malicious instructions inserted by external attackers, leading to Cross Site Request Forgery.Show less
1Jenkins
1Mac
Jun 17, 2026
Mar 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
1Jenkins
1P4
Jun 17, 2026
Mar 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.
1Metagauss
1Registrationmagic
Jun 17, 2026
Mar 6, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting use...Show more
A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.Show less
1Centreon
1Centreon
Jun 17, 2026
Mar 5, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.ph...Show more
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.Show less
1Cisco
1Prime Network Registrar
Jun 17, 2026
Mar 4, 2020
N/A· v4
7.1 HIGH· v3
4.3 MEDIUM· v2
A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerab...Show more
A vulnerability in the web-based interface of Cisco Prime Network Registrar (CPNR) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections in the web-based interface. An attacker could exploit this vulnerability by persuading a targeted user, with an active administrative session on the affected device, to click a malicious link. A successful exploit could allow an attacker to change the device's configuration, which could include the ability to edit or create user accounts of any privilege level. Some changes to the device's configuration could negatively impact the availability of networking services for other devices on networks managed by CPNR.Show less