CWE-352
9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,657)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nortekcontrol 2Linear Emerge Elite Firmware Linear Emerge Essential FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). |
1Nortekcontrol 2Linear Emerge 5000p Firmware Linear Emerge 50p FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF). |
An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection. |
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). |
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visi...Show more |
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets...Show more |
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Jun 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery. |
IBM API Connect 5.0.0.0 through 5.0.8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force...Show more |
1Quadbase 1Espressreport Enterprise Server Jun 17, 2026 Jun 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privileges, or create new admin accounts by crafting a malicious web page that issues specific requests, u...Show more |
The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can cause forgery of a request to an out-of-origin domain. This in turn may allow for a forged request th...Show more |
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due...Show more |
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. T...Show more |
1Cisco 2Integrated Management Controller Unified Computing SystemJun 17, 2026 Jun 20, 2019 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitr...Show more |
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account. |
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account. |
1Securifi 3Almond+firmware Almond 2015 FirmwareAlmond FirmwareNov 21, 2024 Jun 18, 2019 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems tha...Show more |
1Securifi 3Almond+firmware Almond 2015 FirmwareAlmond FirmwareNov 21, 2024 Jun 18, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface....Show more |
1Tubigan 1Welcome To Our Resort Nov 21, 2024 Jun 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit. |