← Back
CWE-352

9,314 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,314)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grandstream
1Ht802 Firmware
May 13, 2026
Nov 6, 2017
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.
1Mahara
1Mahara
May 13, 2026
Nov 3, 2017
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an a...Show more
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading malicious files into their Mahara account.Show less
1Ibm
1Openpages Grc Platform
May 13, 2026
Nov 1, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-...Show more
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162.Show less
1Jenkins
1Favorite
May 13, 2026
Nov 1, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification
1Octobercms
1October
May 13, 2026
Nov 1, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack byp...Show more
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involving X-CSRF headers and CSRF tokens via a certain _handler postback variable.Show less
2Cloudfoundry
Pivotal Software
3Cf Release
Cloud Foundry Elastic RuntimeCloud Foundry Uaa
May 13, 2026
Oct 24, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a use...Show more
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.Show less
1Watchguard
1Hawkeye G
May 13, 2026
Oct 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name par...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/json; turn off the (2) Url matching, (3) DNS Inject, or (4) IP Redirect Sensor in a request to interface/rest/dpi/setEnabled/1; or (5) perform whitelisting of malware MD5 hash IDs via the id parameter to interface/rest/md5-threats/whitelist.Show less
1Letodms Project
1Letodms
May 13, 2026
Oct 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.
1Webmin
1Webmin
May 13, 2026
Oct 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.
1Cisco
2Spa300 Firmware
Spa500 Firmware
May 13, 2026
Oct 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forg...Show more
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCuz88421, CSCuz91356, CSCve56308.Show less
1Alienvault
1Unified Security Management
May 13, 2026
Oct 18, 2017
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script a...Show more
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send out any report via email to a given address (either in PDF or XLS format). Since there is no anti-CSRF token protecting this functionality, it is vulnerable to Cross-Site Request Forgery attacks.Show less
1Realtyna
1Realtyna Property Listing
May 13, 2026
Oct 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an...Show more
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php.Show less