← Back
CWE-352

9,658 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,658)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of user roles.
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
4.3 MEDIUM· v3
5.8 MEDIUM· v2
A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can result in unintended deletion of the store design schedule.
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or...Show more
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper's cart due to an insufficiently robust a...Show more
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can cause unwanted items to be added to a shopper's cart due to an insufficiently robust anti-CSRF token implementation.Show less
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can lead to unintended data deletion from customer pages.
1Redhat
1Openshift Container Platform
Jun 17, 2026
Aug 2, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability...Show more
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.Show less
1Windu
1Windu Cms
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
2Jolokia
Redhat
2Jolokia
Openstack
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer header...Show more
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer headers. This could result in a Remote Code Execution attack.Show less
1Moodle
1Moodle
Jun 17, 2026
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
1Wallaceit
1Wallacepos
Jun 17, 2026
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
1I Lan
1Draytekl Firmware
Nov 21, 2024
Jul 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.
1Jenkins
1M2release
Jun 17, 2026
Jul 31, 2019
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.
1Custom Simple Rss Project
1Custom Simple Rss
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
edx-platform before 2016-06-06 allows CSRF.
1Simple Membership Plugin
1Simple Membership
Jun 17, 2026
Jul 28, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
1Angry Frog
1Xavier
Jun 17, 2026
Jul 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an error when registering the user, the uns...Show more
Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an error when registering the user, the unsanitized username will reflect via the error page. Due to the lack of CSRF protection on the admin/includes/adminprocess.php endpoint, an attacker is able to chain the XSS with CSRF in order to cause remote exploitation.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jul 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159132.
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Jul 23, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerab...Show more
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.Show less
1Wcms
1Wcms
Jun 17, 2026
Jul 23, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.
1Wp Code Highlightjs Project
1Wp Code Highlightjs
Jun 17, 2026
Jul 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css para...Show more
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.Show less