← Back
CWE-352

9,660 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,660)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Topmanage
1Olk Webstore
Jun 17, 2026
Feb 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In TopManage OLK 2020, login CSRF can be chained with another vulnerability in order to takeover admin and user accounts.
1Mozilla
1Persona
Nov 21, 2024
Feb 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication o...Show more
Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type.Show less
1Realestateconnected
1Easy Property Listings
Jun 17, 2026
Feb 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Moodle
1Moodle
Jun 17, 2026
Feb 17, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.
1Prestashop
1Prestashop
Nov 21, 2024
Feb 14, 2020
N/A· v4
5.5 MEDIUM· v3
3.5 LOW· v2
PrestaShop before 1.4.11 allows logout CSRF.
1Paloaltonetworks
1Expedition Migration Tool
Jun 17, 2026
Feb 12, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migra...Show more
Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition Migration Tool 1.1.51 and earlier versions.Show less
1Jenkins
1Pipeline Github Notify Step
Jun 17, 2026
Feb 12, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained throug...Show more
A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Atlassian
3Jira
Jira Data CenterJira Server
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 b...Show more
The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version 7.0.2, and from version 7.1.0 before version 7.1.3. The vulnerable plugin is used by Atlassian Jira Server and Data Center before version 8.7.0. An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.Show less
1Atlassian
2Jira Data Center
Jira Server
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrat...Show more
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.Show less
1Atlassian
2Jira Data Center
Jira Server
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administra...Show more
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open ports on the internal network where Jira server is present.Show less
1Socialengine
1Socialengine
Nov 21, 2024
Feb 11, 2020
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4.
1Maxum
1Rumpus Ftp
Jun 17, 2026
Feb 10, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.
1Maxum
1Rumpus Ftp
Jun 17, 2026
Feb 10, 2020
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could allow an attacker to delete, create, and update the upload forms via RAPR/TriggerServerFunction.html.
1Maxum
1Rumpus Ftp
Jun 17, 2026
Feb 10, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an attacker to whitelist or block any IP address via RAPR/BlockedClients.html.
1Maxum
1Rumpus Ftp
Jun 17, 2026
Feb 10, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can create/update event notices via RAPR/EventNoticesSet.html.
1Maxum
1Rumpus Ftp
Jun 17, 2026
Feb 10, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server Web settings at RAPR/WebSettingsGeneralSet.html.
1Maxum
1Rumpus Ftp
Jun 17, 2026
Feb 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can Create and Delete accounts via RAPR/TriggerServerFunction.html.
1Undolog
1Wp Cleanfix
Nov 21, 2024
Feb 10, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WordPress plugin wp-cleanfix has Remote Code Execution
1Undolog
1Cleanfix
Nov 21, 2024
Feb 10, 2020
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
1Maxum
1Rumpus
Jun 17, 2026
Feb 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server FTP settings at RAPR/FTPSettingsSet.html.