← Back
CWE-352

9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,644)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Interact
May 13, 2026
May 10, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID...Show more
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 115085.Show less
1Codection
1Clean Login
May 13, 2026
May 10, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
1Acquia
1Mautic
May 13, 2026
May 10, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete contacts.
1Asus
1Rt Ac1750 Firmware
May 13, 2026
May 10, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF.
1Allen Disk Project
1Allen Disk
May 13, 2026
May 8, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.
2Netiq
Novell
2Imanager
Imanager
May 13, 2026
May 3, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
1Ibm
1Websphere Application Server
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website tru...Show more
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.Show less
1Ipa
1Appgoat
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecif...Show more
Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.Show less
1Support Project
1Knowledge
May 13, 2026
Apr 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Knowledge versions prior to v1.7.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
1S9y
1Serendipity
May 13, 2026
Apr 24, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.
1Artistscope
1Copysafe Web Protection
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.
1Browserweb Inc
1Whizz
May 13, 2026
Apr 24, 2017
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request.
1E107
1E107
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the...Show more
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.Show less
1Kallithea Scm
1Kallithea
May 13, 2026
Apr 24, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.
1Dlink
26Dcs 2132l Firmware
Dcs 2136l FirmwareDcs 2210l Firmware+23 more
May 13, 2026
Apr 24, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from do...Show more
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device. Known affected devices are DCS-933L with firmware before 1.13.05, DCS-5030L, DCS-5020L, DCS-2530L, DCS-2630L, DCS-930L, DCS-932L, and DCS-932LB1.Show less
1Concretecms
1Concrete Cms
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/f...Show more
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.Show less
3Clusterlabs
FedoraprojectRedhat
3Enterprise Linux
FedoraPcs
May 13, 2026
Apr 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
1Wondercms
1Wondercms
May 13, 2026
Apr 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
1Openmrs
1Openmrs Module Reporting
May 13, 2026
Apr 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
1Redhat
2Jboss Bpm Suite
Jboss Enterprise Brms Platform
May 13, 2026
Apr 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page.