VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 176 of 482
  • CVE-2022-20774MedApr 6, 2022
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an…

  • CVE-2022-0088HigApr 3, 2022
    risk 0.44cvss 7.4epss 0.02

    Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.

  • CVE-2021-34358MedNov 20, 2021
    risk 0.44cvss 6.8epss 0.00

    We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later

  • CVE-2021-24490MedSep 13, 2021
    risk 0.44cvss 6.8epss 0.01

    The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a…

  • CVE-2020-18457MedAug 12, 2021
    risk 0.44cvss 6.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html.

  • CVE-2020-18454MedAug 12, 2021
    risk 0.44cvss 6.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.

  • CVE-2021-32776MedJul 21, 2021
    risk 0.44cvss 6.8epss 0.00

    Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows servers no cleanup is done on CSRF tokens. This issue is fixed in versions 2.7.4 and 3.0.0.

  • CVE-2020-15135MedAug 4, 2020
    risk 0.44cvss 6.7epss 0.01

    save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing…

  • CVE-2019-6607MedMar 28, 2019
    risk 0.44cvss 6.8epss 0.01

    On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability in an ASM violation viewed in the Configuration utility. In the worst case, an attacker can store a CSRF which results in code…

  • CVE-2018-10224MedApr 19, 2018
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.

  • CVE-2018-10223MedApr 19, 2018
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.

  • CVE-2018-5073MedJan 3, 2018
    risk 0.44cvss 6.8epss 0.00

    Online Ticket Booking has CSRF via admin/movieedit.php.

  • CVE-2017-17982MedDec 30, 2017
    risk 0.44cvss 6.8epss 0.00

    PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.

  • CVE-2017-17830MedDec 21, 2017
    risk 0.44cvss 6.8epss 0.00

    Bus Booking Script has CSRF via admin/new_master.php.

  • CVE-2017-1000147MedNov 3, 2017
    risk 0.44cvss 6.8epss 0.00

    Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading…

  • CVE-2009-4139MedJul 27, 2011
    risk 0.44cvss 6.8epss 0.01

    A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or…

  • CVE-2026-72849HigAug 13, 2026
    risk 0.43cvss 7.7epss 0.00

    Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked…

  • CVE-2025-27792HigMar 11, 2025
    risk 0.43cvss epss 0.00

    Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns…

  • CVE-2020-7336MedJan 5, 2021
    risk 0.43cvss 6.6epss 0.01

    Cross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request.

  • CVE-2019-11193MedApr 30, 2019
    risk 0.43cvss 6.1epss 0.02

    The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker can bypass the CSRF protection with this, and take over the administration panel.