CWE-352
9,314 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,314)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. |
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. |
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. |
1Ibm 2Disposal And Governance Management For It Global Retention Policy And Schedule ManagementMay 13, 2026 Apr 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is vulnerable to cross-site request forgery which could allow an attacker...Show more |
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authentic...Show more |
1Jensenofscandinavia 3Al3g Firmware Al5000ac FirmwareAl59300 FirmwareMay 13, 2026 Apr 3, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct CSRF attacks via c...Show more |
1Huawei 32Tecal Bh620 V2 Firmware Tecal Bh621 V2 FirmwareTecal Bh622 V2 Firmware+29 moreMay 13, 2026 Apr 2, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earl...Show more |
1Huawei 6Fusionmanager Usg2100 FirmwareUsg2200 Firmware+3 moreMay 13, 2026 Apr 2, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SP...Show more |
1Huawei 6Fusionmanager Usg2100 FirmwareUsg2200 Firmware+3 moreMay 13, 2026 Apr 2, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface. |
1Ibm 1Sterling Selling And Fulfillment Foundation May 13, 2026 Mar 31, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Referen...Show more |
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other potential CSRF vulnerabil...Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate....Show more |
1Revive Adserver 1Revive Adserver May 13, 2026 Mar 28, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of pa...Show more |
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter. |
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter. |
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter. |
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter. |
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determini...Show more |
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the...Show more |