← Back
CWE-352

9,657 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Slack Notification
Jun 17, 2026
Mar 28, 2019
N/A· v4
7.1 HIGH· v3
2.1 LOW· v2
A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another...Show more
A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less
1S Cms
1S Cms
Jun 17, 2026
Mar 27, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to CVE-2019-9040.
1Moodle
1Moodle
Jun 17, 2026
Mar 25, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. Th...Show more
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.Show less
1Cisco
4Ip Conference Phone 8832 Firmware
Ip Phone 8800 FirmwareIp Phone 8821 Ex Firmware+1 more
Jun 17, 2026
Mar 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (...Show more
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series. Cisco IP Conference Phone 8831 is not affected.Show less
1Jio
1Jiofi 4g M2s Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).
1Rental Bike Script Project
1Rental Bike Script
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
1Zyxel
2Dsl 491hnu B10b Firmware
Dsl 491hnu B1b V2 Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
1Airties
1Air 5341 Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
1Chinamobileltd
1Gpn2.4p21 C Cn Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Passw...Show more
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.Show less
1Car Rental Script Project
1Car Rental Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.
1Basic B2b Script Project
1Basic B2b Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.
1Entrepreneur Job Portal Script Project
1Entrepreneur Job Portal Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
1Advance B2b Script Project
1Advance B2b Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
1Systrome
3Cumilon Isg 600c Firmware
Cumilon Isg 600h FirmwareCumilon Isg 800w Firmware
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of...Show more
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of csrf token validation.Show less
1Ens
1Webgalamb
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator password.
1Layerbb
1Layerbb
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.
1Mybb
1Trash Bin
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.
1Wordpress
1Wordpress
Jun 17, 2026
Mar 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search...Show more
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.Show less
1Kartatopia
1Piluscart
Jun 17, 2026
Mar 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as administrator.
1Rednao
1Smart Forms
Jun 17, 2026
Mar 12, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.