← Back
CWE-352

9,644 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium

Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

JSON object

Loading...

CVEs (9,644)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
1Ruggedcom Rox I
May 13, 2026
Mar 29, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active...Show more
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active session and is induced into clicking on a malicious link or into visiting a malicious website, aka CSRF.Show less
1Revive Adserver
1Revive Adserver
May 13, 2026
Mar 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other potential CSRF vulnerabil...Show more
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other potential CSRF vulnerabilities. Over 20+ such issues were fixed.Show less
1Revive Adserver
1Revive Adserver
May 13, 2026
Mar 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate....Show more
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/banner-advanced.php`, `www/admin/banner-modify.php`, `www/admin/banner-swf.php`, `www/admin/banner-zone.php`, `www/admin/tracker-modify.php`.Show less
1Revive Adserver
1Revive Adserver
May 13, 2026
Mar 28, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of pa...Show more
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of password recovery emails to the registered users, especially in conjunction with a bug that caused recovery emails to be sent to all the users at once. Both issues have been fixed.Show less
1Intelliants
1Subrion Cms
May 13, 2026
Mar 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
1Intelliants
1Subrion Cms
May 13, 2026
Mar 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
1Intelliants
1Subrion Cms
May 13, 2026
Mar 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
1Intelliants
1Subrion Cms
May 13, 2026
Mar 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.
1Mediawiki
1Mediawiki
May 13, 2026
Mar 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determini...Show more
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.Show less
1Mediawiki
1Mediawiki
May 13, 2026
Mar 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the...Show more
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.Show less
1Netiq
1Access Manager
May 13, 2026
Mar 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross site request forgery protection mechanism in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be circumvented by repeated uploads causing a high load.
1D Link
1Dir 600m Firmware
May 13, 2026
Mar 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact.
1Meteocontrol
1Weblog
May 13, 2026
Mar 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per fun...Show more
A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generated per page or per function.Show less
1Juniper
1Junos Space
May 13, 2026
Mar 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
1Solarwinds
1Ftp Voyager
May 13, 2026
Mar 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for request...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute arbitrary commands via crafted requests to Admin/XML/Result.xml.Show less
2Debian
Deluge Torrent
2Debian Linux
Deluge
May 13, 2026
Mar 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to dow...Show more
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.Show less
1Cisco
1Unified Communications Manager
May 13, 2026
Mar 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web i...Show more
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More Information: CSCvb70021. Known Affected Releases: 11.5(1.11007.2).Show less
1Microsoft
3Windows 7
Windows Server 2008Windows Vista
May 13, 2026
Mar 17, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka...Show more
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."Show less
1Drupal
1Drupal
May 13, 2026
Mar 16, 2017
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know...Show more
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.Show less
1Bigtreecms
1Bigtree Cms
May 13, 2026
Mar 15, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.