← Back
CWE-352

9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
1Nortekcontrol
2Linear Emerge 5000p Firmware
Linear Emerge 50p Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
1Cyberpanel
1Cyberpanel
Jun 17, 2026
Jul 2, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.
1Optergy
2Enterprise
Proton
Jun 17, 2026
Jul 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
1Primasystems
1Flexair
Jun 17, 2026
Jul 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visi...Show more
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.Show less
1Wpchef
1Widget Logic
Jun 17, 2026
Jul 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets...Show more
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.Show less
1Peel
1Peel Shopping
Nov 21, 2024
Jun 30, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
1Lenovo
1Service Bridge
Jun 17, 2026
Jun 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
1Ibm
1Api Connect
Nov 21, 2024
Jun 25, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 151256.Show less
1Quadbase
1Espressreport Enterprise Server
Jun 17, 2026
Jun 24, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, u...Show more
CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, using a target admin's session to process their requests.Show less
1Bobronix
1Jeditor
Jun 17, 2026
Jun 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request th...Show more
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request that can be invoked in the context of an authenticated user, leading to stealing of session tokens and account takeover.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Jun 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due...Show more
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or reload an affected device. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software with the HTTP Server feature enabled. The default state of the HTTP Server feature is version dependent.Show less
1Cisco
1Prime Service Catalog
Jun 17, 2026
Jun 20, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. T...Show more
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protection mechanisms on the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.Show less
1Cisco
2Integrated Management Controller
Unified Computing System
Jun 17, 2026
Jun 20, 2019
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitr...Show more
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected device. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to use a web browser and the privileges of the user to perform arbitrary actions on the affected device.Show less
1Ranksol
1Nimble Professional
Nov 21, 2024
Jun 19, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
1Ranksol
1Live Call Support
Nov 21, 2024
Jun 19, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
1Securifi
3Almond+firmware
Almond 2015 FirmwareAlmond Firmware
Nov 21, 2024
Jun 18, 2019
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems tha...Show more
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems that the device does not implement any cross-site scripting forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface into executing a cross-site scripting payload on the user's browser and execute any action on the device provided by the web management interface.Show less
1Securifi
3Almond+firmware
Almond 2015 FirmwareAlmond Firmware
Nov 21, 2024
Jun 18, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface....Show more
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross site request forgery protection mechanism which allows an attacker to trick a user who is logged in to the web management interface to change a user's password. Also this is a systemic issue.Show less
1Tubigan
1Welcome To Our Resort
Nov 21, 2024
Jun 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.