CWE-352
9,349 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,349)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery. |
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more |
1Quadbase 1Espressreport Enterprise Server Jun 17, 2026 Jun 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, u...Show more |
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request th...Show more |
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due...Show more |
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. T...Show more |
1Cisco 2Integrated Management Controller Unified Computing SystemJun 17, 2026 Jun 20, 2019 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitr...Show more |
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account. |
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account. |
1Securifi 3Almond+firmware Almond 2015 FirmwareAlmond FirmwareNov 21, 2024 Jun 18, 2019 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems tha...Show more |
1Securifi 3Almond+firmware Almond 2015 FirmwareAlmond FirmwareNov 21, 2024 Jun 18, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface....Show more |
1Tubigan 1Welcome To Our Resort Nov 21, 2024 Jun 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit. |
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IB...Show more |
1Getvera 2Veraedge Firmware Veralite FirmwareNov 21, 2024 Jun 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deleting apps on the device using the web management interface. It seems that...Show more |
1Hp 10T6b80a Firmware T6b81a FirmwareT6b82a Firmware+7 moreJun 17, 2026 Jun 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an embedded web server that is potentially vulnerable to Cross-s...Show more |
1Microsoft 1Azure Devops Server Jun 17, 2026 Jun 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability c...Show more |
1Zte 1Wf820+ Lte Outdoor Cpe Firmware Jun 17, 2026 Jun 11, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requ...Show more |
A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed attackers to have Jenkins connect to an attacker-specified Kubernetes ser...Show more |
A cross-site request forgery vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed attackers to connect to an attacker-specified URL using attacker-specified credentials...Show more |
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhosts without the consent of the owner. |