← Back
CWE-352

9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpserveur
1Wps Hide Login
Nov 21, 2024
Oct 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
1Ad Inserter Project
1Ad Inserter
Nov 21, 2024
Oct 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
1Openwrt
1Openwrt
Jun 17, 2026
Oct 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under...Show more
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.Show less
1Wikidsystems
12fa Enterprise Server
Jun 17, 2026
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete gr...Show more
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create, delete, enable, or disable normal users or devices.Show less
1Metinfo
1Metinfo
Jun 17, 2026
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
1Cisco
108Sf200 24 Firmware
Sf200 24fp FirmwareSf200 24p Firmware+105 more
Jun 17, 2026
Oct 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affecte...Show more
A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the targeted user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or cause a denial of service (DoS) condition on an affected device.Show less
1Jenkins
1Oracle Cloud Infrastructure Compute Classic
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
1Jenkins
1Rundeck
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
1Jenkins
1Icescrum
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.
1Jenkins
1Crx Content Package Deployer
Jun 17, 2026
Oct 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained thro...Show more
A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Netgear
1Jnr1010 Firmware
Nov 21, 2024
Oct 16, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
1Intelbras
1Iwr 1000n Firmware
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
1Jizhicms
1Jizhicms
Jun 17, 2026
Oct 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
1Landing Cms Project
1Landing Cms
Jun 17, 2026
Oct 12, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,
1Gree
1Gree
Nov 21, 2024
Oct 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery.
2Oracle
Smartbear
6Banking Apis
Banking Digital ExperienceBanking Platform+3 more
Jun 17, 2026
Oct 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltr...Show more
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.Show less
1Eleopard
1Animate It!
Jun 17, 2026
Oct 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
1Fastadmin
1Fastadmin
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row&#91;name&#93; parameter.
1Fastadmin
1Fastadmin
Jun 17, 2026
Oct 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.