← Back
CWE-352

9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fcm Mb40 Firmware
Jun 17, 2026
Jul 8, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.
1Flarum
1Flarum
Jun 17, 2026
Jul 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
1Ignitedcms
1Ignitedcms
Jun 17, 2026
Jul 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
1Waspthemes
1Custom Css Pro
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Fla Shop
1Html5 Maps
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Meomundo
1Related Youtube Videos
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Najeebmedia
1Personalized Woocommerce Cart Page
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Contest Gallery
1Contest Gallery
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Sukimalab
1Online Lesson Booking
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Sukimalab
1Attendance Manager
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Weseek
1Growi
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.
1Zoho
1Salesiq
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1Custom4web
1Wp Open Graph
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1F5
2Big Ip Advanced Firewall Manager
Big Ip Application Security Manager
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.4 HIGH· v3
8.5 HIGH· v2
On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF whic...Show more
On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF which results in code execution as the admin user. The level of user role which can perform this attack are resource administrator and administrator.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.
1Rapid7
1Nexpose
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using F...Show more
A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.Show less
1Open Xchange
1Ox Guard
Nov 21, 2024
Jul 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
OX Guard 2.8.0 has CSRF.
1Moxa
2Oncell G3150 Hspa T Firmware
Oncell G3150 Hspa Firmware
Nov 21, 2024
Jul 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.
1Dlink
1Dcs 1130 Firmware
Nov 21, 2024
Jul 2, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows an hosted flash file on any domain to make calls to the dev...Show more
An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows an hosted flash file on any domain to make calls to the device's webserver and pull any information that is stored on the device. In this case, user's credentials are stored in clear text on the device and can be pulled easily. It also seems that the device does not implement any cross-site scripting forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a cross-site flashing attack on the user's browser and execute any action on the device provided by the web management interface which steals the credentials from tools_admin.cgi file's response and displays it inside a Textfield.Show less
1Dlink
1Dcs 1130 Firmware
Nov 21, 2024
Jul 2, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any...Show more
An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface to change the user's password.Show less