CWE-352
9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,644)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID...Show more |
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL. |
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete contacts. |
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF. |
1Allen Disk Project 1Allen Disk May 13, 2026 May 8, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password. |
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management. |
1Ibm 1Websphere Application Server May 13, 2026 Apr 28, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website tru...Show more |
Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecif...Show more |
Cross-site request forgery (CSRF) vulnerability in Knowledge versions prior to v1.7.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors. |
There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request. |
1Artistscope 1Copysafe Web Protection May 13, 2026 Apr 24, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings. |
There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request. |
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the...Show more |
Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method. |
1Dlink 26Dcs 2132l Firmware Dcs 2136l FirmwareDcs 2210l Firmware+23 moreMay 13, 2026 Apr 24, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from do...Show more |
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/f...Show more |
3Clusterlabs FedoraprojectRedhat3Enterprise Linux FedoraPcsMay 13, 2026 Apr 21, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. |
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context. |
1Openmrs 1Openmrs Module Reporting May 13, 2026 Apr 21, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp. |
1Redhat 2Jboss Bpm Suite Jboss Enterprise Brms PlatformMay 13, 2026 Apr 20, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page. |