CWE-352
9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,658)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request fr...Show more |
1Smackcoders 1Ultimate Exporter Nov 21, 2024 Aug 14, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF. |
1Smackcoders 1Import All Pages, Post Types, Products, Orders, And Users As Xml & Csv Nov 21, 2024 Aug 14, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. |
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface. |
1Supsystic 1Newsletter By Supsystic Nov 21, 2024 Aug 14, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF. |
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF. |
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions. |
The wp-editor plugin before 1.2.6 for WordPress has CSRF. |
1Simple Membership Plugin 1Simple Membership Nov 21, 2024 Aug 14, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues. |
1Mijnpress 1Simple Add Pages Or Posts Nov 21, 2024 Aug 14, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. |
1Google Doc Embedder Project 1Google Doc Embedder Nov 21, 2024 Aug 14, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The google-document-embedder plugin before 2.6.2 for WordPress has CSRF. |
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. |
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. |
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. |
1Simple Fields Project 1Simple Fields Nov 21, 2024 Aug 14, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface. |
1Tibco 22Loglogic Enterprise Virtual Appliance Loglogic Log Management IntelligenceLoglogic Lx1025 Firmware+19 moreJun 17, 2026 Aug 13, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and refl...Show more |
1Codepeople 1Contact Form Email Nov 21, 2024 Aug 13, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. |
1Wpdeveloper 1Twitter Cards Meta Nov 21, 2024 Aug 12, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF. |
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF. |
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF. |