CWE-352
9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,657)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload it...Show more |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. |
1Westermo 3Dr 250 Firmware Dr 260 FirmwareMr 260 FirmwareNov 21, 2024 May 24, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF. |
1Schneider Electric 59D6220 Firmware D6220l FirmwareD6230 Firmware+56 moreJun 17, 2026 May 22, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into...Show more |
1Mylittleforum 1My Little Forum Jun 17, 2026 May 21, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting. |
1Wpbookingsystem 1Wp Booking System Jun 17, 2026 May 20, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL injection issues that require administrative access. |
An issue was discovered in the administrator interface in IPBRICK OS 6.3. The application doesn't check for Anti-CSRF tokens, allowing the submission of multiple forms unwillingly by a victim. |
Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs. |
1Yellowpencil 1Visual Css Style Editor Jun 17, 2026 May 13, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access. |
1Ibm 1Financial Transaction Manager Nov 21, 2024 May 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a u...Show more |
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the...Show more |
Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in...Show more |
JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser request and then reading the token field. This token value can then be used to cha...Show more |
1Ibm 1Curam Social Program Management Nov 21, 2024 May 7, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Cram Social Program Management 6.1.1, 6.2.0, 7.0.4, and 7.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the w...Show more |
1Phoenixcontact 29Fl Switch 3004t Fx Firmware Fl Switch 3004t Fx St FirmwareFl Switch 3005 Firmware+26 moreNov 21, 2024 May 7, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF. |
Veeam ONE Reporter 9.5.0.3201 allows CSRF. |
1Sierrawireless 1Airlink Es450 Firmware Nov 21, 2024 May 6, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable cross-site request forgery vulnerability exists in the ACEManager functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause an authenticated user to perform privil...Show more |
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to p...Show more |
In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes on the server configuration without the user consent, requiring the attacker to lure an authenticat...Show more |
1Cisco 14Hx220c Af M5 Firmware Hx220c All Nvme M5 FirmwareHx220c Edge M5 Firmware+11 moreJun 17, 2026 May 3, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an...Show more |