← Back
CWE-352

9,659 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,659)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Health Advisor By Cloudbees
Jun 17, 2026
Jan 15, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient.
1Jenkins
1Amazon Ec2
Jun 17, 2026
Jan 15, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained th...Show more
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.Show less
1Phpbb
1Phpbb
Jun 17, 2026
Jan 15, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.
1Phpbb
1Phpbb
Jun 17, 2026
Jan 15, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.
1Websitebaker
1Websitebaker
Nov 21, 2024
Jan 14, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.
1Free
1Freebox Os
Nov 21, 2024
Jan 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
1Ricoh
52M 2700 Firmware
M 2701 FirmwareM C250fw Firmware+49 more
Jun 17, 2026
Jan 10, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Ricoh SP C250DN 1.06 devices allow CSRF.
1Peel
1Peel Shopping
Jun 17, 2026
Jan 9, 2020
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.
1Hp
8Deskjet 3630 F5s43a Firmware
Deskjet 3630 F5s57a FirmwareDeskjet 3630 K4t93a Firmware+5 more
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that coul...Show more
HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.Show less
1Webfactoryltd
1Minimal Coming Soon & Maintenance Mode
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
1Hp
8Deskjet 3630 F5s43a Firmware
Deskjet 3630 F5s57a FirmwareDeskjet 3630 K4t93a Firmware+5 more
Jun 17, 2026
Jan 9, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability t...Show more
Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that could lead to a denial of service (DOS) or device misconfiguration.Show less
1Prophecyinternational
1Snare
Nov 21, 2024
Jan 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Snare for Linux before 1.7.0 has CSRF in the web interface.
1Typesettercms
1Typesetter
Jun 17, 2026
Jan 5, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability.
1Konakart
1Konakart
Nov 21, 2024
Jan 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for requests that change a u...Show more
Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for requests that change a user email address via an unspecified GET request.Show less
1Redhat
1Satellite
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content.
1Opsview
2Opsview
Opsview Core
Nov 21, 2024
Jan 2, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator p...Show more
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.Show less
1Zenphoto
1Zenphoto
Nov 21, 2024
Dec 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumpt...Show more
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).Show less
1Outsystems
1Outsystems
Jun 17, 2026
Dec 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain...Show more
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain name.) NOTE: The vendor claims that the independent researcher created the report without any type of validation and that no such vulnerability existsShow less
1Redhat
1Openshift
Nov 21, 2024
Dec 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Au...Show more
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.Show less
1Mfscripts
1Yetishare
Jun 17, 2026
Dec 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks.