CWE-352
9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,658)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft a malicious CSRF payload that can result in arbitrary command execution...Show more |
2Debian Horde2Debian Linux GroupwareNov 21, 2024 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php. |
3Debian HordeOpensuse3Debian Linux GroupwareOpensuseNov 21, 2024 Nov 5, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions |
2Debian Horde2Debian Linux GroupwareNov 21, 2024 Nov 5, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book |
1Oneidentity 1Cloud Access Manager Jun 17, 2026 Nov 4, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests. |
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload. |
An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code through a /reports-viewScriptReport.view CSRF vulnerability. |
Tiki Wiki CMS Groupware 5.2 has CSRF |
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities. |
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure. |
1Sourcecodester 1Restaurant Management System Jun 17, 2026 Oct 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator...Show more |
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags co...Show more |
1Darktrace 1Enterprise Immune System Jun 17, 2026 Oct 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint. |
1Darktrace 1Enterprise Immune System Jun 17, 2026 Oct 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint. |
1Online Grading System Project 1Online Grading System Jun 17, 2026 Oct 23, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code...Show more |
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This...Show more |
A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, captur...Show more |
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another...Show more |
A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an...Show more |
1Jenkins 1Dynatrace Application Monitoring Jun 17, 2026 Oct 23, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials. |