CWE-352
9,659 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,659)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Health Advisor By Cloudbees Jun 17, 2026 Jan 15, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient. |
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained th...Show more |
phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships. |
phpBB 3.2.8 allows a CSRF attack that can modify a group avatar. |
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions. |
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation |
1Ricoh 52M 2700 Firmware M 2701 FirmwareM C250fw Firmware+49 moreJun 17, 2026 Jan 10, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Ricoh SP C250DN 1.06 devices allow CSRF. |
Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user. |
1Hp 8Deskjet 3630 F5s43a Firmware Deskjet 3630 F5s57a FirmwareDeskjet 3630 K4t93a Firmware+5 moreJun 17, 2026 Jan 9, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability that coul...Show more |
1Webfactoryltd 1Minimal Coming Soon & Maintenance Mode Jun 17, 2026 Jan 9, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo. |
1Hp 8Deskjet 3630 F5s43a Firmware Deskjet 3630 F5s57a FirmwareDeskjet 3630 K4t93a Firmware+5 moreJun 17, 2026 Jan 9, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Certain HP DeskJet 3630 All-in-One Printers models F5S43A - F5S57A, K4T93A - K4T99C, K4U00B - K4U03B, and V3F21A - V3F22A (firmware version SWP1FN1912BR or higher) have a Cross-Site Request Forgery (CSRF) vulnerability t...Show more |
Snare for Linux before 1.7.0 has CSRF in the web interface. |
The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel is not protected by any CSRF tokens. An attacker can logout the user using this vulnerability. |
Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for requests that change a u...Show more |
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content. |
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator p...Show more |
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumpt...Show more |
OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE: The product is self-hosted by the customer, even though it has a *.outsystemsenterprise.com domain...Show more |
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Au...Show more |
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks. |