← Back
CWE-352

9,660 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,660)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Metalgenix
1Genixcms
Jun 17, 2026
Mar 4, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but witho...Show more
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.Show less
1Phpipam
1Phpipam
Jun 17, 2026
Mar 4, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exi...Show more
An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens.Show less
1Netgear
1Wnr1000 Firmware
Jun 17, 2026
Mar 2, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demo...Show more
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management console are vulnerable to an unauthenticated GET request (exploitable directly or through CSRF), as demonstrated by the setup.cgi?todo=save_htp_account URI.Show less
1Atutor
1Atutor
Nov 21, 2024
Mar 2, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.Show less
1Cloudfoundry
2Cf Deployment
User Account And Authentication
Jun 17, 2026
Feb 27, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
1Puppet
1Puppet Enterprise
Nov 21, 2024
Feb 27, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a...Show more
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.Show less
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Feb 26, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that th...Show more
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172363.Show less
1Seling
1Visual Access Manager
Jun 17, 2026
Feb 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An attacker can exploit the vulnerability to abuse functionalities such as...Show more
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery (CSRF) on any HTML form. An attacker can exploit the vulnerability to abuse functionalities such as change password, add user, add privilege, and so on.Show less
1Supsystic
1Pricing Table By Supsystic
Jun 17, 2026
Feb 25, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.
1Litecart
1Litecart
Jun 17, 2026
Feb 25, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.
1Miele
1Xgw 3000 Zigbee Gateway Firmware
Jun 17, 2026
Feb 24, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.
1Auieo
1Candidats
Jun 17, 2026
Feb 22, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.
1Axous
1Axous
Nov 21, 2024
Feb 20, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an admi...Show more
Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to admin/administrators_add.php; or (2) conduct cross-site scripting (XSS) attacks via the page_title parameter to admin/content_pages_edit.php; the (3) category_name[] parameter to admin/products_category.php; the (4) site_name, (5) seo_title, or (6) meta_keywords parameter to admin/settings_siteinfo.php; the (7) company_name, (8) address1, (9) address2, (10) city, (11) state, (12) country, (13) author_first_name, (14) author_last_name, (15) author_email, (16) contact_first_name, (17) contact_last_name, (18) contact_email, (19) general_email, (20) general_phone, (21) general_fax, (22) sales_email, (23) sales_phone, (24) support_email, or (25) support_phone parameter to admin/settings_company.php; or the (26) system_email, (27) sender_name, (28) smtp_server, (29) smtp_username, (30) smtp_password, or (31) order_notice_email parameter to admin/settings_email.php.Show less
1Cisco
1Data Center Network Manager
Jun 17, 2026
Feb 19, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected syste...Show more
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link while having an active session on an affected device. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user.Show less
1Silverstripe
1Silverstripe
Jun 17, 2026
Feb 19, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In SilverStripe through 4.3.3, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations,
1Silverstripe
1Silverstripe
Jun 17, 2026
Feb 19, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools.
1Icehrm
1Icehrm
Jun 17, 2026
Feb 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to user creation via service.php.
1Icehrm
1Icehrm
Jun 17, 2026
Feb 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ICE Hrm 26.2.0 is vulnerable to CSRF that leads to password reset via service.php.
1Soplanning
1Soplanning
Jun 17, 2026
Feb 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
1Soplanning
1Soplanning
Jun 17, 2026
Feb 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.