← Back
CWE-352

9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Universal Plugin Manager
Jun 17, 2026
Aug 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins u...Show more
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collectio...Show more
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via...Show more
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).Show less
1Atlassian
2Jira
Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site reque...Show more
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.Show less
1It Novum
1Openitcockpit
Jun 17, 2026
Aug 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
1Codection
1Import Users From Csv With Meta
Jun 17, 2026
Aug 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
1Pippinsplugins
1Featured Comments
Nov 21, 2024
Aug 22, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
1Supsystic
1Photo Gallery
Nov 21, 2024
Aug 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
1Control Webpanel
1Webpanel
Jun 17, 2026
Aug 21, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
1Cisco
1Ios Xe
Jun 17, 2026
Aug 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and pe...Show more
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.Show less
1Wp Kama
1Democracy Poll
Nov 21, 2024
Aug 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.
1Godaddy
1Godaddy Email Marketing
Nov 21, 2024
Aug 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
1Gowebsolutions
1Wp Customer Reviews
Nov 21, 2024
Aug 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
1Ibm
1Storediq
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158700.
1Ibm
1Cloud Private
Jun 17, 2026
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 1...Show more
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158116.Show less
1Eelv Newsletter Project
1Eelv Newsletter
Nov 21, 2024
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
1Cformsii Project
1Cformsii
Jun 17, 2026
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
1Mythemeshop
1My Wp Translate
Nov 21, 2024
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
1Supsystic
1Popup
Nov 21, 2024
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
1Add From Server Project
1Add From Server
Nov 21, 2024
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.