CWE-352
9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,644)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Read And Understood Project 1Read And Understood Jun 17, 2026 Jan 13, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php. |
1Responsive Coming Soon Page Project 1Responsive Coming Soon Page Jun 17, 2026 Jan 13, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php. |
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php. |
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change...Show more |
1Ibm 1Security Identity Manager Nov 21, 2024 Jan 12, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users...Show more |
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability. |
1Srbtranslatin Project 1Srbtranslatin Nov 21, 2024 Jan 12, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php. |
The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php. |
1Haudenschilt 1Family Connections Cms Nov 21, 2024 Jan 11, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an...Show more |
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability". |
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433. |
The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php. |
1Ibm 1Security Key Lifecycle Manager Nov 21, 2024 Jan 4, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-...Show more |
1Advanced Real Estate Script Project 1Advanced Real Estate Script Nov 21, 2024 Jan 3, 2018 N/A· v4 6.8 MEDIUM· v3 6.0 MEDIUM· v2 Online Ticket Booking has CSRF via admin/movieedit.php. |
2Netgate Opnsense Project2Opnsense PfsenseNov 21, 2024 Jan 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is s...Show more |
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, droppin...Show more |
1Vanillaforums 1Vanilla Forums Nov 21, 2024 Jan 2, 2018 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access |
1Iwcnetwork 1Biometric Shift Employee Management System May 13, 2026 Dec 30, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action. |
1Muslim Matrimonial Script Project 1Muslim Matrimonial Script May 13, 2026 Dec 30, 2017 N/A· v4 6.8 MEDIUM· v3 6.0 MEDIUM· v2 PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php. |
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated...Show more |