← Back
CWE-352

9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Layerbb
1Layerbb
Jun 17, 2026
Jul 19, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
LayerBB 1.1.3 allows conversations.php/cmd/new CSRF.
1Adobe
1Experience Manager
Jun 17, 2026
Jul 18, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager version 6.4 and ealier have a Cross-Site Request Forgery vulnerability. Successful exploitation could lead to Sensitive Information disclosure in the context of the current user.
1Flatcore
1Flatcore
Jun 17, 2026
Jul 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
1Phpcoo
1Oecms
Jun 17, 2026
Jul 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connec...Show more
OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3.Show less
1Audiocodes
4Mediant 500 Mbsr Firmware
Mediant 500l Msbr FirmwareMediant 800c Msbr Firmware+1 more
Jun 17, 2026
Jul 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web int...Show more
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.Show less
1Syguestbook A5 Project
1Syguestbook A5
Jun 17, 2026
Jul 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.
1Domainmod
1Domainmod
Jun 17, 2026
Jul 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user to admin. The component is: admin/users/edit.php?uid=2. The attack vect...Show more
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user to admin. The component is: admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html page.Show less
1Domainmod
1Domainmod
Jun 17, 2026
Jul 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator account. The component is: admin/users/add.php. The attack vector is: After...Show more
DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can add the administrator account. The component is: admin/users/add.php. The attack vector is: After the administrator logged in, open the html page.Show less
1Domainmod
1Domainmod
Jun 17, 2026
Jul 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The component is: http://127.0.0.1/settings/password/ http://127.0.0.1/adm...Show more
domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The component is: http://127.0.0.1/settings/password/ http://127.0.0.1/admin/users/add.php http://127.0.0.1/admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html page.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jul 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password cha...Show more
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jul 17, 2019
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
1Python Engineio Project
1Python Engineio
Jun 17, 2026
Jul 16, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, b...Show more
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.Show less
1Mirumee
1Saleor
Jun 17, 2026
Jul 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
1Dlink
1Dir 655 Firmware
Jun 17, 2026
Jul 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
1Mybb 2fa Project
1Mybb 2fa
Jun 17, 2026
Jul 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plugin to control its state via usercp.php?action=mybb2fa&do=deactivate (o...Show more
An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a request to an installed mybb2fa plugin to control its state via usercp.php?action=mybb2fa&do=deactivate (or usercp.php?action=mybb2fa&do=activate). A deactivate operation lowers the security of the targeted account by disabling two factor authentication.Show less
1Jenkins
1Docker
Jun 17, 2026
Jul 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using atta...Show more
A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
Jun 17, 2026
Jul 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Wikimedia MediaWiki through 1.32.1 allows CSRF.
1Cyberpowersystems
1Powerpanel
Jun 17, 2026
Jul 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user i...Show more
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.Show less
1Eventum Project
1Eventum
Nov 21, 2024
Jul 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges.
1Mailenable
1Mailenable
Jun 17, 2026
Jul 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from t...Show more
In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.Show less