CWE-352
9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,658)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wp Buy 1Visitor Traffic Real Time Statistics Jun 17, 2026 Aug 30, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. |
1Wp Buy 1Visitor Traffic Real Time Statistics Jun 17, 2026 Aug 30, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. |
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. |
The photo-gallery plugin before 1.2.42 for WordPress has CSRF. |
1Weblizar 1Social Likebox & Feed Jun 17, 2026 Aug 29, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF. |
1Quadlayers 1Wp Social Feed Gallery Jun 17, 2026 Aug 29, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete. |
1Hallme 1Woocommerce Address Book Jun 17, 2026 Aug 29, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. |
1Haktansuren 1Handl Utm Grabber Jun 17, 2026 Aug 29, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. |
1Lexmark 25Cs31x Firmware Cs41x FirmwareCx310 Firmware+22 moreJun 17, 2026 Aug 28, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Various Lexmark products have CSRF. |
1Manageyourteam 1Myt Project Management Jun 17, 2026 Aug 28, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Aug 28, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for th...Show more |
Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportun...Show more |
The wp-members plugin before 3.2.8 for WordPress has CSRF. |
1Elearningfreak 1Insert Or Embed Articulate Content Jun 17, 2026 Aug 27, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. |
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. |
1Bbpress Move Topics Project 1Bbpress Move Topics Nov 21, 2024 Aug 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF. |
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. |
The wp-rollback plugin before 1.2.3 for WordPress has CSRF. |
Discourse 2.3.2 sends the CSRF token in the query string. |
The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability. |