VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 127 of 482
  • CVE-2016-4430HigJul 4, 2016
    risk 0.50cvss 8.8epss 0.04

    Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

  • CVE-2016-2157HigMay 22, 2016
    risk 0.50cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests…

  • CVE-2015-5338HigFeb 22, 2016
    risk 0.50cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1)…

  • CVE-2015-7538HigFeb 3, 2016
    risk 0.50cvss 8.8epss 0.02

    Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.

  • CVE-2015-7537HigFeb 3, 2016
    risk 0.50cvss 8.8epss 0.02

    Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

  • CVE-2015-8379HigJan 26, 2016
    risk 0.50cvss 8.8epss 0.01

    CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

  • CVE-2026-16262HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity…

  • CVE-2026-7326HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can…

  • CVE-2026-46955HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-11265HigJun 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-34896HigApr 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1.

  • CVE-2024-53684HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.

  • CVE-2025-63955HigNov 18, 2025
    risk 0.49cvss 7.5epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts,…

  • CVE-2025-62771HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.

  • CVE-2025-54052HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows PHP Local File Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.0.0.

  • CVE-2025-24289HigJun 29, 2025
    risk 0.49cvss 7.5epss 0.00

    A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.

  • CVE-2025-2111HigApr 19, 2025
    risk 0.49cvss 7.5epss 0.00

    The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'custom_plugin_set_option' function. This makes it possible for…

  • CVE-2023-48790HigMar 11, 2025
    risk 0.49cvss 7.5epss 0.00

    A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests.

  • CVE-2025-24900HigFeb 11, 2025
    risk 0.49cvss 8.6epss 0.00

    Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper settings of cookies for MediaProxy authentication, there is a vulnerability that allows MediaProxy authentication to be bypassed. In…

  • CVE-2025-22963HigJan 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.