← Back
CWE-352

9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,644)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Read And Understood Project
1Read And Understood
Jun 17, 2026
Jan 13, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php.
1Responsive Coming Soon Page Project
1Responsive Coming Soon Page
Jun 17, 2026
Jan 13, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php.
1Weblizar
1Pinterest Feeds
Jun 17, 2026
Jan 13, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php.
1Fiberhome
1Lm53q1 Firmware
Nov 21, 2024
Jan 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change...Show more
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.Show less
1Ibm
1Security Identity Manager
Nov 21, 2024
Jan 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users...Show more
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736.Show less
1Atlassian
1Jira
Nov 21, 2024
Jan 12, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.
1Srbtranslatin Project
1Srbtranslatin
Nov 21, 2024
Jan 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php.
1Wpglobus
1Wpglobus
Nov 21, 2024
Jan 12, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.
1Haudenschilt
1Family Connections Cms
Nov 21, 2024
Jan 11, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2) add a prayer via an add action to prayers.php.Show less
1Microsoft
1Asp.net Core
Nov 21, 2024
Jan 10, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
1Magento
1Magento
Nov 21, 2024
Jan 8, 2018
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.
1Wpscoop
1Imageinject
Nov 21, 2024
Jan 8, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php.
1Ibm
1Security Key Lifecycle Manager
Nov 21, 2024
Jan 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-...Show more
IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133639.Show less
1Advanced Real Estate Script Project
1Advanced Real Estate Script
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
Online Ticket Booking has CSRF via admin/movieedit.php.
2Netgate
Opnsense Project
2Opnsense
Pfsense
Nov 21, 2024
Jan 3, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is s...Show more
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from the code during an internal security audit under "possibly insecure" suspicions.Show less
1Phpmyadmin
1Phpmyadmin
Nov 21, 2024
Jan 3, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, droppin...Show more
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.Show less
1Vanillaforums
1Vanilla Forums
Nov 21, 2024
Jan 2, 2018
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
1Iwcnetwork
1Biometric Shift Employee Management System
May 13, 2026
Dec 30, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.
1Muslim Matrimonial Script Project
1Muslim Matrimonial Script
May 13, 2026
Dec 30, 2017
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
2Hawt
Redhat
2Hawtio
Jboss Fuse
May 13, 2026
Dec 29, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated...Show more
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f."Show less