← Back
CWE-352

9,314 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,314)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1C.p.sub Project
1C.p.sub
Jun 17, 2026
Feb 11, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
1Verydows
1Verydows
Jun 17, 2026
Feb 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.
1Mywebsql
1Mywebsql
Jun 17, 2026
Feb 11, 2019
N/A· v4
5.7 MEDIUM· v3
4.9 MEDIUM· v2
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
1Traq
1Traq
Nov 21, 2024
Feb 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
1Pbootcms
1Pbootcms
Jun 17, 2026
Feb 7, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
1Wdoyo
1Doyo
Jun 17, 2026
Feb 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1.
1Cszcms
1Csz Cms
Jun 17, 2026
Feb 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSZ CMS 1.1.8 has CSRF via admin/users/new/add.
1Jenkins
1Monitoring
Jun 17, 2026
Feb 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master.
1Jenkins
1Job Import
Jun 17, 2026
Feb 6, 2019
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from a preconfigured other Jenkins instance, potentially installing additio...Show more
A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from a preconfigured other Jenkins instance, potentially installing additional plugins necessary to load the imported job's configuration.Show less
1Jenkins
1Job Import
Jun 17, 2026
Feb 6, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/JobImportAction.java, src/main/java/org/jenkins/ci/plugins/jobimpor...Show more
An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/JobImportAction.java, src/main/java/org/jenkins/ci/plugins/jobimport/JobImportGlobalConfig.java, src/main/java/org/jenkins/ci/plugins/jobimport/model/JenkinsSite.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
2Jenkins
Redhat
2Blue Ocean
Openshift Container Platform
Jun 17, 2026
Feb 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-...Show more
A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-core-js/src/js/urlconfig.js, blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java, blueocean-web/src/main/java/io/jenkins/blueocean/BlueOceanUI.java, blueocean-web/src/main/resources/io/jenkins/blueocean/BlueOceanUI/index.jelly that allows attackers to bypass all cross-site request forgery protection in Blue Ocean API.Show less
2Jenkins
Redhat
2Git
Openshift Container Platform
Jun 17, 2026
Feb 6, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach correspo...Show more
A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.Show less
1Jenkins
1Warnings Next Generation
Jun 17, 2026
Feb 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/analysis/warnings/groovy/GroovyParser.java that allows attackers to execu...Show more
A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/analysis/warnings/groovy/GroovyParser.java that allows attackers to execute arbitrary code via a form validation HTTP endpoint.Show less
1Jenkins
1Warnings
Jun 17, 2026
Feb 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability exists in Jenkins Warnings Plugin 5.0.0 and earlier in src/main/java/hudson/plugins/warnings/GroovyParser.java that allows attackers to execute arbitrary code via a form validat...Show more
A cross-site request forgery vulnerability exists in Jenkins Warnings Plugin 5.0.0 and earlier in src/main/java/hudson/plugins/warnings/GroovyParser.java that allows attackers to execute arbitrary code via a form validation HTTP endpoint.Show less
1Phpmywind
1Phpmywind
Jun 17, 2026
Feb 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF.
1Taoensso
1Sente
Jun 17, 2026
Feb 4, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token. This attack appe...Show more
Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket handshake endpoint that can result in CSRF attack, possible leak of anti-CSRF token. This attack appears to be exploitable via malicious request against WebSocket handshake endpoint. This vulnerability appears to have been fixed in 1.14.0 and later.Show less
1Mapsvg
1Mapsvg Lite
Jun 17, 2026
Feb 4, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embe...Show more
MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/admin-ajax.php?action=mapsvg_save that can result in an attacker can modify post data, including embedding javascript. This attack appears to be exploitable via the victim must be logged in to WordPress as an admin, and click a link. This vulnerability appears to have been fixed in 3.3.0 and later.Show less
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 4, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack succ...Show more
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful.Show less
1Mcafee
1Epolicy Orchestrator
Jun 17, 2026
Feb 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vectors.
1Chshcms
1Cscms
Jun 17, 2026
Jan 24, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.