← Back
CWE-352

9,659 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,659)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netis Systems
1Dl4343 Firmware
Jun 17, 2026
Dec 30, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
1Dlink
1Dwr 113 Firmware
Nov 21, 2024
Dec 27, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password...Show more
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors.Show less
1Spbas
1Business Automation Software
Nov 21, 2024
Dec 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
SPBAS Business Automation Software 2012 has CSRF.
1Intelbras
1Iwr 3000n Firmware
Jun 17, 2026
Dec 26, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user.
1Dlink
1Dir 601 Firmware
Jun 17, 2026
Dec 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE...Show more
D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE: this is an end-of-life product.Show less
1Custom Body Class Project
1Custom Body Class
Jun 17, 2026
Dec 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Wpspellcheck
1Wpspellcheck
Jun 17, 2026
Dec 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Icegram
1Email Subscribers & Newsletters
Jun 17, 2026
Dec 26, 2019
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
1Wp Maintenance Project
1Wp Maintenance
Jun 17, 2026
Dec 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS.
1Ibm
1Financial Transaction Manager For Multiplatform
Jun 17, 2026
Dec 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force I...Show more
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172706.Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Dec 20, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID:...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.Show less
1Ibm
1Cognos Business Intelligence
Nov 21, 2024
Dec 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more
IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153179.Show less
1Webfactoryltd
1301 Redirects
Jun 17, 2026
Dec 19, 2019
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=...Show more
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a loss of site availability, malicious redirects, and user infections. This could also be exploited via CSRF.Show less
1Eclipse
1Che
Jun 17, 2026
Dec 19, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually...Show more
For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.Show less
1Tautulli
1Tautulli
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a user login area).
1Xerox
1Altalink C8035 Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
1Microfocus
1Arcsight Logger
Jun 17, 2026
Dec 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery vulnerability in all Micro Focus ArcSight Logger affecting all product versions below version 7.0. The vulnerability could be exploited to perform CSRF attack.
1Jenkins
1Alauda Kubernetes Support
Jun 17, 2026
Dec 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through a...Show more
A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing the Kubernetes service account token or credentials stored in Jenkins.Show less
1Jenkins
1Alauda Devops Pipeline
Jun 17, 2026
Dec 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through ano...Show more
A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Rapiddeploy
Jun 17, 2026
Dec 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server.