← Back
CWE-352

9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,644)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
1Phpmyfaq
1Phpmyfaq
May 13, 2026
Oct 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.
1Webmin
1Webmin
May 13, 2026
Oct 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.
1Cisco
2Spa300 Firmware
Spa500 Firmware
May 13, 2026
Oct 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forg...Show more
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCuz88421, CSCuz91356, CSCve56308.Show less
1Alienvault
1Unified Security Management
May 13, 2026
Oct 18, 2017
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script a...Show more
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send out any report via email to a given address (either in PDF or XLS format). Since there is no anti-CSRF token protecting this functionality, it is vulnerable to Cross-Site Request Forgery attacks.Show less
1Realtyna
1Realtyna Property Listing
May 13, 2026
Oct 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an...Show more
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php.Show less
1Keycloak
1Keycloak
May 13, 2026
Oct 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
1Prominent
1Multiflex M10a Controller Firmware
May 13, 2026
Oct 17, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site request forgery. This may...Show more
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site request forgery. This may allow an attacker to execute unauthorized code, resulting in changes to the configuration of the device.Show less
1Sap
1Customer Relationship Management
May 13, 2026
Oct 16, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
1Juniper
1Junos Space
May 13, 2026
Oct 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authe...Show more
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected.Show less
1Juniper
1Junos
May 13, 2026
Oct 13, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).
1Jantek
1Jtc 200 Firmware
May 13, 2026
Oct 13, 2017
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to...Show more
A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.Show less
1Phpbugtracker Project
1Phpbugtracker
May 13, 2026
Oct 6, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that cause an unspecified impact via unknown...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that cause an unspecified impact via unknown parameters.Show less
1Phpbugtracker Project
1Phpbugtracker
May 13, 2026
Oct 6, 2017
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack the authentication of users for requests that cause an unspecified impa...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack the authentication of users for requests that cause an unspecified impact via the id parameter to project.php, (2) hijack the authentication of users for requests that cause an unspecified impact via the group_id parameter to group.php, (3) hijack the authentication of users for requests that delete statuses via the status_id parameter to status.php, (4) hijack the authentication of users for requests that delete severities via the severity_id parameter to severity.php, (5) hijack the authentication of users for requests that cause an unspecified impact via the priority_id parameter to priority.php, (6) hijack the authentication of users for requests that delete the operating system via the os_id parameter to os.php, (7) hijack the authentication of users for requests that delete databases via the database_id parameter to database.php, or (8) hijack the authentication of users for requests that delete sites via the site_id parameter to sites.php.Show less
1Rapid7
1Metasploit
May 13, 2026
Oct 6, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
1Intelliants
1Subrion
May 13, 2026
Oct 6, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for...Show more
There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to panel/database.Show less