← Back
CWE-352

9,660 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,660)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Maxum
1Rumpus
Jun 17, 2026
Feb 10, 2020
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attacker to Create/Delete Folders after exploiting it at RAPR/FolderSetsSet.html.
1Maxum
1Rumpus
Jun 17, 2026
Feb 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkS...Show more
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html.Show less
1Maxum
1Rumpus
Jun 17, 2026
Feb 10, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details,...Show more
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details, and escalate privileges via RAPR/DefineUsersSet.html.Show less
1Mfscripts
1Yetishare
Jun 17, 2026
Feb 10, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and...Show more
payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection. NOTE: this issue exists because of an incomplete fix for CVE-2019-19732.Show less
1Ui
3Airvision Controller
Mfi ControllerUnifi Controller
Nov 21, 2024
Feb 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified impact via a request to api/add/wlanconf; change the guest (3) password, (4) authentication method, or (5) restricted subnets via a request to api/set/setting/guest_access; (6) block, (7) unblock, or (8) reconnect users by MAC address via a request to api/cmd/stamgr; change the syslog (9) server or (10) port via a request to api/set/setting/rsyslogd; (11) have unspecified impact via a request to api/set/setting/smtp; change the syslog (12) server, (13) port, or (14) authentication settings via a request to api/cmd/cfgmgr; or (15) change the Unifi Controller name via a request to api/set/setting/identity.Show less
1Smoothwall
1Smoothwall Express
Nov 21, 2024
Feb 7, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF vulnerability in Smoothwall Express 3.
1Kemptechnologies
1Load Master
Nov 21, 2024
Feb 7, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
1Cisco
1Linksys Wrt110 Firmware
Nov 21, 2024
Feb 6, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
1Dd Wrt
1Dd Wrt
Nov 21, 2024
Feb 6, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
1Bestwebsoft
1Htaccess
Jun 17, 2026
Feb 6, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not valida...Show more
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.Show less
1Atlassian
2Jira Data Center
Jira Server
Jun 17, 2026
Feb 6, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
1Atlassian
1Jira Server
Jun 17, 2026
Feb 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
1Batavi
1Batavi
Nov 21, 2024
Feb 5, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Batavi before 1.0 has CSRF.
1Ibm
1Planning Analytics
Jun 17, 2026
Feb 5, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 168524.
1Themeum
1Tutor Lms
Jun 17, 2026
Feb 4, 2020
N/A· v4
6.5 MEDIUM· v3
2.6 LOW· v2
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves as an instructor and performing other malicious actions (such as blocking legitimate instructors).
1Phppgadmin Project
1Phppgadmin
Jun 17, 2026
Feb 4, 2020
N/A· v4
9.6 CRITICAL· v3
9.3 HIGH· v2
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This ca...Show more
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in administrator to visit a malicious page with a CSRF exploit and execute arbitrary system commands on the server.Show less
1Dlink
1Dir 100 Firmware
Nov 21, 2024
Feb 4, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
D-Link DIR-100 4.03B07: cli.cgi CSRF
1Arox
1School Management Software Php/mysql
Jun 17, 2026
Jan 31, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.
1Arox
1School Management Software Php/mysql
Jun 17, 2026
Jan 31, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.
1Wowza
1Streaming Engine
Jun 17, 2026
Jan 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via e...Show more
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza Streaming Engine 4.8.5.Show less