← Back
CWE-352

9,660 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,660)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webargs Project
1Webargs
Jun 17, 2026
Jan 29, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is appli...Show more
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.Show less
1Cups Easy (purchase & Inventory) Project
1Cups Easy (purchase & Inventory)
Jun 17, 2026
Jan 28, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
1Cups Easy Project
1Cups Easy
Jun 17, 2026
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
1Joomla
1Joomla
Jun 17, 2026
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
1Joomla
1Joomla
Jun 17, 2026
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.
1Codesnippets
1Code Snippets
Jun 17, 2026
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.
1Asus
7Dsl N55u Firmware
Rt Ac66u FirmwareRt N10u Firmware+4 more
Nov 21, 2024
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
ASUS RT-N56U devices allow CSRF.
1Private Only Project
1Private Only
Nov 21, 2024
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or (4) conduct cross-site scripting (XSS) attacks via the po_logo parameter in the privateonly.php page to wp-admin/options-general.php.Show less
1Micasaverde
1Veralite Firmware
Nov 21, 2024
Jan 28, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware...Show more
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.Show less
1Adive
1Framework
Jun 17, 2026
Jan 26, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
1Owncloud
2Owncloud
Owncloud Server
Mar 31, 2025
Jan 23, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP H...Show more
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.Show less
1Connectwise
1Control
Jun 17, 2026
Jan 23, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.
1Umbraco
1Umbraco Cms
Jun 17, 2026
Jan 23, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
1Usebb
1Usebb
Nov 21, 2024
Jan 22, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
1Anelectron
1Advanced Electron Forums
Nov 21, 2024
Jan 22, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
1Hutchhouse
1Marketo Forms And Tracking
Jun 17, 2026
Jan 21, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
1Redhat
1Quay
Jun 17, 2026
Jan 21, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or...Show more
A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.Show less
2Oracle
Vmware
27Application Testing Suite
Communications Brm Elastic Charging EngineCommunications Diameter Signaling Router+24 more
Jun 17, 2026
Jan 17, 2020
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-a...Show more
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.Show less
1Serpico Project
1Serpico
Jun 17, 2026
Jan 15, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it uses the Origin header (which must match the request origin). This is...Show more
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens to mitigate against CSRF; it uses the Origin header (which must match the request origin). This is problematic in conjunction with XSS: one can escalate privileges from User level to Administrator.Show less
1Osisoft
1Pi Vision
Jun 17, 2026
Jan 15, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.