← Back
CWE-352

9,659 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,659)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
FedoraprojectSquid Cache
3Fedora
SquidUbuntu Linux
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message proce...Show more
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.Show less
1Cisco
1Sd Wan Firmware
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerabi...Show more
A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected instance of vManage. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.Show less
1Redhat
1Jboss Application Server
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag)...Show more
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a specially-crafted web page provided by a remote attacker.Show less
1D Link
1Dsl6740u Firmware
Nov 21, 2024
Nov 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credential...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port Forwarding, (2) Port Triggering Entries, (3) URL Filters in Parental Control, (4) Print Server settings, (5) QoS Queue Setup, or (6) QoS Classification Entries.Show less
1Pagekit
1Pagekit
Jun 17, 2026
Nov 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
1Drupal
1Activity
Nov 21, 2024
Nov 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
1Synametrics
3Synaman
SyncrifySyntail
Nov 21, 2024
Nov 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567
1Loftek
1Nexus 543 Firmware
Nov 21, 2024
Nov 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewa...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi.Show less
1Jenkins
1Google Compute Engine
Jun 17, 2026
Nov 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used to provision new agents.
1Cobblerd
1Cobbler
Nov 21, 2024
Nov 19, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
cobbler: Web interface lacks CSRF protection when using Django framework
13xlogic
1Infinias Access Control Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a...Show more
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document or encoded URL to a user that the website trusts. The user needs to have an active privileged session.Show less
1Trendnet
1Tew 812dru Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
1Fairsketch
1Rise Ultimate Project Manager
Jun 17, 2026
Nov 13, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
1Netgear
2Wnr3500l Firmware
Wnr3500u Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.
2Debian
Trilexnet
2Debian Linux
Letodms
Nov 21, 2024
Nov 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
letodms 3.3.6 has CSRF via change password
1Redhat
2Jboss Enterprise Web Server
Keycloak
Nov 21, 2024
Nov 13, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
1Pixelpost
1Pixelpost
Nov 21, 2024
Nov 12, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
1Getigniteup
1Igniteup
Jun 17, 2026
Nov 12, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Nov 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and...Show more
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.Show less
1Joomla
1Joomla
Jun 17, 2026
Nov 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.