← Back
CWE-352

9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sma
1Sunny Webbox Firmware
Jul 13, 2026
Oct 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device u...Show more
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.Show less
1Otcms
1Otcms
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.
1Incsub
1Buddypress Activity Plus
Nov 21, 2024
Oct 7, 2019
N/A· v4
8.1 HIGH· v3
7.8 HIGH· v2
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
1Vzug
1Combi Stream Mslq Firmware
Jun 17, 2026
Oct 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service.
1Cisco
3Unified Communications Manager
Unified Communications Manager Im And Presence ServiceUnity Connection
Jun 17, 2026
Oct 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM...Show more
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections by the affected software. An attacker could exploit this vulnerability by persuading a targeted user to click a malicious link. A successful exploit could allow the attacker to send arbitrary requests that could change the password of a targeted user. An attacker could then take unauthorized actions on behalf of the targeted user.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Oct 2, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
2Debian
Phpbb
2Debian Linux
Phpbb
Jun 17, 2026
Sep 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to r...Show more
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.Show less
1Phpbb
1Phpbb
Jun 17, 2026
Sep 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
1Netgate
1Pfsense
Jun 17, 2026
Sep 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try...Show more
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.Show less
1Unitegallery
1Unite Gallery Lite
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
1Unitegallery
1Unite Gallery Lite
Nov 21, 2024
Sep 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
1Wp Accurate Form Data Project
1Wp Accurate Form Data
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.
1Avenirsoft
1Directdownload
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.
1Bookmarkify Project
1Bookmarkify
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.
1Monetize Project
1Monetize
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.
1Vivwebsolutions
1Dynamic Widgets
Nov 27, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.
1Kiwi Logo Carousel Project
1Kiwi Logo Carousel
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter.
1Wp Social Bookmarking Light Project
1Wp Social Bookmarking Light
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-l...Show more
The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php.Show less
1Thealpinepress
1Alpine Photo Tile For Instagram
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
1Qtranslate X Project
1Qtranslate X
Nov 21, 2024
Sep 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.