CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 176 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-20774 | Med | 0.44 | 6.8 | 0.00 | Apr 6, 2022 | A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an… | ||
| CVE-2022-0088 | Hig | 0.44 | 7.4 | 0.02 | Apr 3, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. | ||
| CVE-2021-34358 | Med | 0.44 | 6.8 | 0.00 | Nov 20, 2021 | We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later | ||
| CVE-2021-24490 | Med | 0.44 | 6.8 | 0.01 | Sep 13, 2021 | The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a… | ||
| CVE-2020-18457 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html. | ||
| CVE-2020-18454 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2021 | Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html. | ||
| CVE-2021-32776 | Med | 0.44 | 6.8 | 0.00 | Jul 21, 2021 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0. | ||
| CVE-2020-15135 | Med | 0.44 | 6.7 | 0.01 | Aug 4, 2020 | save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing… | ||
| CVE-2019-6607 | Med | 0.44 | 6.8 | 0.01 | Mar 28, 2019 | On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability in an ASM violation viewed in the Configuration utility. In the worst case, an attacker can store a CSRF which results in code… | ||
| CVE-2018-10224 | Med | 0.44 | 6.8 | 0.00 | Apr 19, 2018 | An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html. | ||
| CVE-2018-10223 | Med | 0.44 | 6.8 | 0.00 | Apr 19, 2018 | An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html. | ||
| CVE-2018-5073 | Med | 0.44 | 6.8 | 0.00 | Jan 3, 2018 | Online Ticket Booking has CSRF via admin/movieedit.php. | ||
| CVE-2017-17982 | Med | 0.44 | 6.8 | 0.00 | Dec 30, 2017 | PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php. | ||
| CVE-2017-17830 | Med | 0.44 | 6.8 | 0.00 | Dec 21, 2017 | Bus Booking Script has CSRF via admin/new_master.php. | ||
| CVE-2017-1000147 | Med | 0.44 | 6.8 | 0.00 | Nov 3, 2017 | Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading… | ||
| CVE-2009-4139 | Med | 0.44 | 6.8 | 0.01 | Jul 27, 2011 | A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or… | ||
| CVE-2026-72849 | Hig | 0.43 | 7.7 | 0.00 | Aug 13, 2026 | Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked… | ||
| CVE-2025-27792 | Hig | 0.43 | — | 0.00 | Mar 11, 2025 | Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns… | ||
| CVE-2020-7336 | Med | 0.43 | 6.6 | 0.01 | Jan 5, 2021 | Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request. | ||
| CVE-2019-11193 | Med | 0.43 | 6.1 | 0.02 | Apr 30, 2019 | The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel. |
- risk 0.44cvss 6.8epss 0.00
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an…
- risk 0.44cvss 7.4epss 0.02
Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
- risk 0.44cvss 6.8epss 0.00
We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later
- risk 0.44cvss 6.8epss 0.01
The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a…
- risk 0.44cvss 6.8epss 0.00
Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html.
- risk 0.44cvss 6.8epss 0.00
Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
- risk 0.44cvss 6.8epss 0.00
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.
- risk 0.44cvss 6.7epss 0.01
save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing…
- risk 0.44cvss 6.8epss 0.01
On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability in an ASM violation viewed in the Configuration utility. In the worst case, an attacker can store a CSRF which results in code…
- risk 0.44cvss 6.8epss 0.00
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.
- risk 0.44cvss 6.8epss 0.00
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.
- risk 0.44cvss 6.8epss 0.00
Online Ticket Booking has CSRF via admin/movieedit.php.
- risk 0.44cvss 6.8epss 0.00
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
- risk 0.44cvss 6.8epss 0.00
Bus Booking Script has CSRF via admin/new_master.php.
- risk 0.44cvss 6.8epss 0.00
Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading…
- risk 0.44cvss 6.8epss 0.01
A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or…
- risk 0.43cvss 7.7epss 0.00
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked…
- risk 0.43cvss —epss 0.00
Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns…
- risk 0.43cvss 6.6epss 0.01
Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.
- risk 0.43cvss 6.1epss 0.02
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.