CWE-352
9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,644)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of...Show more |
1Zohocorp 1Password Manager Pro May 13, 2026 Apr 20, 2017 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500). |
1Aveva 1Wonderware Intouch Access Anywhere May 13, 2026 Apr 20, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external si...Show more |
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header....Show more |
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations. |
Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecified vectors. |
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user. |
An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an...Show more |
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings. |
1Axis 1Axis Communications Firmware May 13, 2026 Apr 10, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi. |
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. |
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. |
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. |
1Ibm 2Disposal And Governance Management For It Global Retention Policy And Schedule ManagementMay 13, 2026 Apr 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is vulnerable to cross-site request forgery which could allow an attacker...Show more |
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authentic...Show more |
1Jensenofscandinavia 3Al3g Firmware Al5000ac FirmwareAl59300 FirmwareMay 13, 2026 Apr 3, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct CSRF attacks via c...Show more |
1Huawei 32Tecal Bh620 V2 Firmware Tecal Bh621 V2 FirmwareTecal Bh622 V2 Firmware+29 moreMay 13, 2026 Apr 2, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earl...Show more |
1Huawei 6Fusionmanager Usg2100 FirmwareUsg2200 Firmware+3 moreMay 13, 2026 Apr 2, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SP...Show more |
1Huawei 6Fusionmanager Usg2100 FirmwareUsg2200 Firmware+3 moreMay 13, 2026 Apr 2, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface. |
1Ibm 1Sterling Selling And Fulfillment Foundation May 13, 2026 Mar 31, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Referen...Show more |