← Back
CWE-352

9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webkul
1Bagisto
Jun 17, 2026
Aug 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Bagisto 0.1.5 allows CSRF under /admin URIs.
123systems
1Lightbox Plus Colorbox
Nov 21, 2024
Aug 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
1Elementalpath
1Cognitoys Dino Firmware
Nov 21, 2024
Aug 8, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Cognitoys Dino devices allow profiles_add.html CSRF.
1Edimax
27237rpd Firmware
Ew 7438rpn Mini Firmware
Nov 21, 2024
Aug 8, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
1Neetcables
1Airstream Nas Firmware
Nov 21, 2024
Aug 8, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
16kbbs
16kbbs
Nov 21, 2024
Aug 8, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
1Codection
1Import Users From Csv With Meta
Jun 17, 2026
Aug 8, 2019
N/A· v4
5.7 MEDIUM· v3
4.9 MEDIUM· v2
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.
1Acf\
1 Better Search Project
Jun 17, 2026
Aug 8, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?page=acfbs_admin_page CSRF.
1Deny All Firewall Project
1Deny All Firewall
Jun 17, 2026
Aug 8, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.
1Mijnpress
1Admin Renamer Extended
Jun 17, 2026
Aug 8, 2019
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.
1Reputeinfosystems
1Arprice Lite
Jun 17, 2026
Aug 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.
1Cisco
1Hyperflex Hx Data Platform
Jun 17, 2026
Aug 8, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerabi...Show more
A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.Show less
1Jenkins
1Relution Enterprise Appstore Publisher
Jun 17, 2026
Aug 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to have Jenkins initiate an HTTP connection to an attacker-specified server.
1Jenkins
1Xl Testview
Jun 17, 2026
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL usi...Show more
A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Jenkins
1Jclouds
Jun 17, 2026
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read a...Show more
A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1Neetcables
1Airstream Nas Firmware
Nov 21, 2024
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.
1Microdigital
3Mdc N2190v Firmware
Mdc N4090 FirmwareMdc N4090w Firmware
Jun 17, 2026
Aug 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF issue was discovered in webparam?user&action=set&param=add in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 to create an admin account.
1Schben
1Adive
Jun 17, 2026
Aug 6, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
1Daskeyboard
1Das Q Software
Jun 17, 2026
Aug 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request with an attacker-controlled releaseUrl, which triggers download and execution of c...Show more
Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin /install request with an attacker-controlled releaseUrl, which triggers download and execution of code within a ZIP archive.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to...Show more
A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.Show less