CWE-352
9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,658)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value. |
1Ad Inserter Project 1Ad Inserter Nov 21, 2024 Oct 22, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. |
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under...Show more |
1Wikidsystems 12fa Enterprise Server Jun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete gr...Show more |
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. |
1Cisco 108Sf200 24 Firmware Sf200 24fp FirmwareSf200 24p Firmware+105 moreJun 17, 2026 Oct 16, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affecte...Show more |
1Jenkins 1Oracle Cloud Infrastructure Compute Classic Jun 17, 2026 Oct 16, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials. |
A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials. |
A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials. |
1Jenkins 1Crx Content Package Deployer Jun 17, 2026 Oct 16, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained thro...Show more |
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter. |
1Intelbras 1Iwr 1000n Firmware Jun 17, 2026 Oct 15, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled. |
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator. |
1Landing Cms Project 1Landing Cms Jun 17, 2026 Oct 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI, |
The GREE+ (aka com.gree.greeplus) application 1.4.0.8 for Android suffers from Cross Site Request Forgery. |
2Oracle Smartbear6Banking Apis Banking Digital ExperienceBanking Platform+3 moreJun 17, 2026 Oct 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltr...Show more |
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php. |
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter. |
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability. |