CWE-352
9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,658)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Atlassian 1Universal Plugin Manager Jun 17, 2026 Aug 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins u...Show more |
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collectio...Show more |
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via...Show more |
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site reque...Show more |
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. |
1Codection 1Import Users From Csv With Meta Jun 17, 2026 Aug 22, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. |
1Pippinsplugins 1Featured Comments Nov 21, 2024 Aug 22, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment. |
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF. |
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account. |
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and pe...Show more |
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n. |
1Godaddy 1Godaddy Email Marketing Nov 21, 2024 Aug 21, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF. |
1Gowebsolutions 1Wp Customer Reviews Nov 21, 2024 Aug 21, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools. |
IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158700. |
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 1...Show more |
1Eelv Newsletter Project 1Eelv Newsletter Nov 21, 2024 Aug 20, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book. |
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. |
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF. |
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF. |
1Add From Server Project 1Add From Server Nov 21, 2024 Aug 20, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file. |