← Back
CWE-352

9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kliqqi
1Kliqqi Cms
Nov 21, 2024
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload it...Show more
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.Show less
1Computrols
1Computrols Building Automation Software
Jun 17, 2026
May 24, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
1Westermo
3Dr 250 Firmware
Dr 260 FirmwareMr 260 Firmware
Nov 21, 2024
May 24, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
1Schneider Electric
59D6220 Firmware
D6220l FirmwareD6230 Firmware+56 more
Jun 17, 2026
May 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into...Show more
A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into the camera.Show less
1Mylittleforum
1My Little Forum
Jun 17, 2026
May 21, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.
1Wpbookingsystem
1Wp Booking System
Jun 17, 2026
May 20, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access.
1Ipbrick
1Ipbrick Os
Nov 21, 2024
May 13, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF tokens, allowing the submission of multiple forms unwillingly by a victim.
1Asus
1Rt Ac3200 Firmware
Nov 21, 2024
May 13, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs.
1Yellowpencil
1Visual Css Style Editor
Jun 17, 2026
May 13, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.
1Ibm
1Financial Transaction Manager
Nov 21, 2024
May 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a u...Show more
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 148944.Show less
1Metinfo
1Metinfo
Nov 21, 2024
May 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the...Show more
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.Show less
1Metinfo
1Metinfo
Nov 21, 2024
May 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in...Show more
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in the login state.Show less
1Jio
1Jmr1140 Firmware
Jun 17, 2026
May 7, 2019
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value can then be used to cha...Show more
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value can then be used to change the Wi-Fi password or perform a factory reset.Show less
1Ibm
1Curam Social Program Management
Nov 21, 2024
May 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the w...Show more
IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 154891.Show less
1Phoenixcontact
29Fl Switch 3004t Fx Firmware
Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 more
Nov 21, 2024
May 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.
1Veeam
1One Reporter
Jun 17, 2026
May 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
1Sierrawireless
1Airlink Es450 Firmware
Nov 21, 2024
May 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privil...Show more
An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privileged requests unknowingly, resulting in unauthenticated requests being requested through an authenticated user. An attacker can get an authenticated user to request authenticated pages on the attacker's behalf to trigger this vulnerability.Show less
1Twitter
1Twitter Kit
Jun 17, 2026
May 6, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to p...Show more
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login with Twitter" authentication information is passed back to the application using the registered custom URL scheme (typically twitterkit-<consumer-key>) on iOS. Because the callback handler did not verify the authenticity of the response, this step is vulnerable to forgery, potentially allowing attacker to associate a Twitter account with a third-party service.Show less
1Ui
1Unifi Video
Jun 17, 2026
May 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticat...Show more
In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticated user to access on attacker controlled page.Show less
1Cisco
14Hx220c Af M5 Firmware
Hx220c All Nvme M5 FirmwareHx220c Edge M5 Firmware+11 more
Jun 17, 2026
May 3, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an...Show more
A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system by using a web browser and with the privileges of the user.Show less