← Back
CWE-352

9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Magento
1Magento
Jun 17, 2026
Nov 5, 2019
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution...Show more
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution.Show less
2Debian
Horde
2Debian Linux
Groupware
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
3Debian
HordeOpensuse
3Debian Linux
GroupwareOpensuse
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
2Debian
Horde
2Debian Linux
Groupware
Nov 21, 2024
Nov 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
1Oneidentity
1Cloud Access Manager
Jun 17, 2026
Nov 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
1Zucchetti
1Infobusiness
Jun 17, 2026
Oct 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
1Labkey
1Labkey Server
Jun 17, 2026
Oct 29, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability.
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Oct 28, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Tiki Wiki CMS Groupware 5.2 has CSRF
1Tp Link
1Tl Wdr4300 Firmware
Nov 21, 2024
Oct 25, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
1Adobe
1Experience Manager
Jun 17, 2026
Oct 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Sourcecodester
1Restaurant Management System
Jun 17, 2026
Oct 24, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator...Show more
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a crafted HTML page.Show less
1Horde
1Groupware
Jun 17, 2026
Oct 24, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags co...Show more
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.Show less
1Darktrace
1Enterprise Immune System
Jun 17, 2026
Oct 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
1Darktrace
1Enterprise Immune System
Jun 17, 2026
Oct 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
1Online Grading System Project
1Online Grading System
Jun 17, 2026
Oct 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code...Show more
Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code via a crafted HTML page, as demonstrated by a Create User action at the admin/modules/user/controller.php?action=add URI.Show less
1Sitemagic
1Sitemagic
Jun 17, 2026
Oct 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This...Show more
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated attacker to trick Sitemagic users into performing unwarranted actions.Show less
1Jenkins
1Libvirt Slaves
Jun 17, 2026
Oct 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, captur...Show more
A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Kubernetes Ci
Jun 17, 2026
Oct 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another...Show more
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Deploy Weblogic
Jun 17, 2026
Oct 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an...Show more
A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file system.Show less
1Jenkins
1Dynatrace Application Monitoring
Jun 17, 2026
Oct 23, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.