← Back
CWE-352

9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,644)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Php Multivendor Ecommerce Project
1Php Multivendor Ecommerce
May 13, 2026
Dec 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
1Single Theater Booking Script Project
1Single Theater Booking Script
May 13, 2026
Dec 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.
1Vanguard Project
1Marketplace Digital Products Php
May 13, 2026
Dec 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Vanguard Marketplace Digital Products PHP has CSRF via /search.
1Ordermanagementscript
1Professional Service Script
May 13, 2026
Dec 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.
1Responsive Realestate Script Project
1Responsive Realestate Script
May 13, 2026
Dec 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.
1Car Rental Script Project
1Car Rental Script
May 13, 2026
Dec 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.
1Fortunescripts
1Lynda Clone
May 13, 2026
Dec 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
1Basic Job Site Script Project
1Basic Job Site Script
May 13, 2026
Dec 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Readymade Job Site Script has CSRF via the /job URI.
1Readymade Video Sharing Script Project
1Readymade Video Sharing Script
May 13, 2026
Dec 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Readymade Video Sharing Script has CSRF via user-profile-edit.php.
1Doditsolutions
1Bus Booking Script
May 13, 2026
Dec 21, 2017
N/A· v4
6.8 MEDIUM· v3
6.0 MEDIUM· v2
Bus Booking Script has CSRF via admin/new_master.php.
1Piwigo
1Piwigo
May 13, 2026
Dec 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration&section=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing uni...Show more
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration&section=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.Show less
1Cambiumnetworks
5Cnpilot E400 Firmware
Cnpilot E410 FirmwareCnpilot E600 Firmware+2 more
May 13, 2026
Dec 20, 2017
N/A· v4
8.0 HIGH· v3
5.4 MEDIUM· v2
Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any...Show more
Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones.Show less
1Ibm
1Jazz For Service Management
May 13, 2026
Dec 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the websi...Show more
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.Show less
1Ibm
1Jazz For Service Management
May 13, 2026
Dec 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the websi...Show more
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133140.Show less
1Piwigo
1Piwigo
May 13, 2026
Dec 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
admin/configuration.php in Piwigo 2.9.2 has CSRF.
1Trendmicro
1Scanmail
May 13, 2026
Dec 16, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
1Rapid7
1Nexpose
May 13, 2026
Dec 14, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) at...Show more
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.Show less
1Microfocus
1Project And Portfolio Management
May 13, 2026
Dec 13, 2017
N/A· v4
7.3 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Cross-Site Forgery attack.
1Zkteco
1Zktime Web
May 13, 2026
Dec 4, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component, reachable via the old_password, new_pa...Show more
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component, reachable via the old_password, new_password1, and new_password2 parameters to the /accounts/password_change/ URI. An attacker takes advantage of this scenario and creates a crafted CSRF link to add himself as an administrator to the ZKTime Web Software. He then uses social engineering methods to trick the administrator into clicking the forged HTTP request. The request is executed and the attacker becomes the Administrator of the ZKTime Web Software. If the vulnerability is successfully exploited, then an attacker (who would be a normal user of the web application) can escalate his privileges and become the administrator of ZKTime Web Software.Show less
1Apache
1Cxf Fediz
May 13, 2026
Nov 30, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3 and Spring 4...Show more
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3 and Spring 4 plugins in versions before 1.4.3 and 1.3.3. The vulnerability can result in a security context that is set up using a malicious client's roles for the given enduser.Show less