VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 15 of 479
  • CVE-2025-55040HigMar 18, 2026
    risk 0.57cvss 8.8epss 0.00

    The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests…

  • CVE-2016-20034HigMar 16, 2026
    risk 0.57cvss 8.8epss 0.00

    Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin'…

  • CVE-2025-70031HigMar 9, 2026
    risk 0.57cvss 8.8epss 0.00

    An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

  • CVE-2025-12821HigFeb 19, 2026
    risk 0.57cvss 8.8epss 0.00

    The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers…

  • CVE-2026-25812HigFeb 9, 2026
    risk 0.57cvss 8.8epss 0.00

    PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enables credentialed CORS requests but does not implement any CSRF protection mechanism.

  • CVE-2025-68722HigFeb 5, 2026
    risk 0.57cvss 8.8epss 0.00

    Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin interface through improper handling of the _s (breadcrumb) parameter. The application accepts state-changing requests via the GET method and…

  • CVE-2026-24345HigJan 27, 2026
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to the admin UI

  • CVE-2026-23622HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while…

  • CVE-2026-22194HigJan 9, 2026
    risk 0.57cvss 8.8epss 0.00

    GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the…

  • CVE-2022-50804HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.00

    JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions on behalf of authenticated users without their knowledge or consent.

  • CVE-2024-30855HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.

  • CVE-2019-25254HigDec 24, 2025
    risk 0.57cvss 8.8epss 0.00

    KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious web pages that automatically submit forms to add new admin accounts with…

  • CVE-2025-66953HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.00

    CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based management interface and specifically the /system_setup.htm, /set_clock.htm, /receiver_setup.htm, /cal.htm?..., and /channel_setup.htm…

  • CVE-2025-65593HigDec 16, 2025
    risk 0.57cvss 8.8epss 0.00

    nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.

  • CVE-2025-65472HigDec 11, 2025
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Administrator via user interaction with a malicious web page.

  • CVE-2020-36901HigDec 10, 2025
    risk 0.57cvss 8.8epss 0.00

    UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet…

  • CVE-2020-36900HigDec 10, 2025
    risk 0.57cvss 8.8epss 0.00

    All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft a malicious web page that automatically submits forms to create a new user…

  • CVE-2020-36886HigDec 10, 2025
    risk 0.57cvss 8.8epss 0.00

    SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new…

  • CVE-2021-47730HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authentication. Attackers can craft a malicious web page that submits a form to add a new admin user with full system privileges when a…

  • CVE-2021-47723HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.00

    STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to…