← Back
CWE-352

9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wordpress Uninstall Project
1Wordpress Uninstall
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI.
1User Domain Whitelist Project
1User Domain Whitelist
Nov 21, 2024
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
1User Access Manager Project
1User Access Manager
Nov 21, 2024
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The user-access-manager plugin before 1.2 for WordPress has CSRF.
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
1Schine.games
1Mw Oauth2client
Jun 17, 2026
Aug 19, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function.
1Profilepress
1Loginwp
Jun 17, 2026
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
1Ncrafts
1Formcraft
Jun 17, 2026
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
1Codeermeneer
1Companion Sitemap Generator
Jun 17, 2026
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
1Joomsky
1Js Job Manager
Nov 21, 2024
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The js-jobs plugin before 1.0.7 for WordPress has CSRF.
1Codeermeneer
1Companion Auto Update
Nov 21, 2024
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
1Churchadminplugin
1Church Admin
Nov 21, 2024
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
1Neliosoftware
1Nelio Ab Testing
Nov 21, 2024
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
1Jayj Quicktag Project
1Jayj Quicktag
Nov 21, 2024
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
1Invite Anyone Project
1Invite Anyone
Nov 21, 2024
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
1Erident Custom Login And Dashboard Project
1Erident Custom Login And Dashboard
Nov 21, 2024
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
1Osisoft
1Pi Web Api
Jun 17, 2026
Aug 15, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.
1Clickhouse
1Clickhouse
Jun 25, 2025
Aug 15, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Aug 14, 2019
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over...Show more
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)Show less
1Netgear
1Mr1100 Firmware
Jun 17, 2026
Aug 14, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in...Show more
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the intended security benefits of the use of a CSRF-protection token.Show less
1Wp Svg Icons Project
1Wp Svg Icons
Jun 17, 2026
Aug 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP a...Show more
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP archive containing a .php file.Show less