CWE-352
9,659 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,659)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical FedoraprojectSquid Cache3Fedora SquidUbuntu LinuxJun 17, 2026 Nov 26, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message proce...Show more |
A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerabi...Show more |
1Redhat 1Jboss Application Server Nov 21, 2024 Nov 26, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag)...Show more |
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credential...Show more |
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request. |
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. |
1Synametrics 3Synaman SyncrifySyntailNov 21, 2024 Nov 21, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewa...Show more |
1Jenkins 1Google Compute Engine Jun 17, 2026 Nov 21, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used to provision new agents. |
cobbler: Web interface lacks CSRF protection when using Django framework |
13xlogic 1Infinias Access Control Firmware Jun 17, 2026 Nov 14, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a...Show more |
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3. |
1Fairsketch 1Rise Ultimate Project Manager Jun 17, 2026 Nov 13, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users. |
1Netgear 2Wnr3500l Firmware Wnr3500u FirmwareNov 21, 2024 Nov 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens. |
2Debian Trilexnet2Debian Linux LetodmsNov 21, 2024 Nov 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 letodms 3.3.6 has CSRF via change password |
1Redhat 2Jboss Enterprise Web Server KeycloakNov 21, 2024 Nov 13, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 JBoss KeyCloak is vulnerable to soft token deletion via CSRF |
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password. |
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Nov 6, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and...Show more |
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability. |