← Back
CWE-352

9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,644)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Techroutes
1Tr 1803 3g Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Techroutes TR 1803-3G Wireless Cellular Router/Modem 2.4.25 devices do not possess any protection against a CSRF vulnerability, as demonstrated by a goform/BasicSettings request to disable port filtering.
1Ibm
1Infosphere Master Data Management Server
May 13, 2026
Jul 31, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a use...Show more
IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729.Show less
1Ibm
1Infosphere Master Data Management Server
May 13, 2026
Jul 31, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from...Show more
IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727.Show less
2Arris
Cisco
2Dpc3939b Firmware
Tg1682g Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configuration changes via CSRF.
2Cisco
Commscope
2Arris Tg1682g Firmware
Dpc3939b Firmware
May 13, 2026
Jul 31, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.
1Netcomm
24gt101w Bootloader
4gt101w Software
May 13, 2026
Jul 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They does not contain an...Show more
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They does not contain any token that can mitigate CSRF vulnerabilities within the device.Show less
1Project Hashtopussy
1Hashtopussy
May 13, 2026
Jul 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) exists in Hashtopussy 0.4.0, allowing an admin password change via users.php.
1Hashtopus Project
1Hashtopus
May 13, 2026
Jul 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) exists in Hashtopus 1.5g via the password parameter to admin.php in an a=config action.
1Subsonic
1Subsonic
May 13, 2026
Jul 25, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a podcast via the add pa...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a podcast via the add parameter to podcastReceiverAdmin.view or (2) update Internet Radio Settings via the urlRedirectCustomUrl parameter to networkSettings.view. NOTE: These vulnerabilities can be exploited to conduct server-side request forgery (SSRF) attacks.Show less
1Buffalo
2Wmr 433 Firmware
Wmr 433w Firmware
May 13, 2026
Jul 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vect...Show more
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.Show less
1Subsonic
1Subsonic
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests that change passwords via a crafted reque...Show more
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests that change passwords via a crafted request to userSettings.view.Show less
1Koha
1Koha
May 13, 2026
Jul 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a cr...Show more
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a crafted list name.Show less
1Greenpacket
1Dx 350 Firmware
May 13, 2026
Jul 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by a request to ajax.cgi that enables UPnP.
1Ibm
1Bigfix Platform
May 13, 2026
Jul 19, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Tivoli Endpoint Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123858.
1Glpi Project
1Glpi
May 13, 2026
Jul 19, 2017
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application.
1Vanderbilt
1Redcap
May 13, 2026
Jul 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
1Kaspersky
1Anti Virus For Linux Server
May 13, 2026
Jul 17, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authentic...Show more
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.Show less
1Apache
1Openmeetings
May 13, 2026
Jul 17, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.
1Oauth2 Proxy Project
1Oauth2 Proxy
May 13, 2026
Jul 17, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF in Bitly oauth2_proxy 2.1 during authentication flow
1Chyrp Lite Project
1Chyrp Lite
May 13, 2026
Jul 17, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.