VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 192 of 482
  • CVE-2022-1599MedJul 11, 2022
    risk 0.42cvss 6.5epss 0.01

    The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date,…

  • CVE-2022-1576MedJul 11, 2022
    risk 0.42cvss 6.5epss 0.01

    The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

  • CVE-2015-1785MedJul 7, 2022
    risk 0.42cvss 6.5epss 0.01

    In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing…

  • CVE-2021-31679MedJul 6, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other members' account numbers.

  • CVE-2021-31678MedJul 6, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company.

  • CVE-2021-31677MedJul 6, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwords.

  • CVE-2022-1967MedJul 4, 2022
    risk 0.42cvss 6.5epss 0.01

    The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and…

  • CVE-2022-34789MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds.

  • CVE-2022-1843MedJun 27, 2022
    risk 0.42cvss 6.5epss 0.01

    The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin change the settings, purge log files and more via CSRF attacks

  • CVE-2022-34211MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL.

  • CVE-2022-34209MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified URL.

  • CVE-2022-34207MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.

  • CVE-2022-34205MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL.

  • CVE-2022-1832MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable the applied protection.

  • CVE-2022-1831MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.00

    The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1830MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.00

    The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation…

  • CVE-2022-1829MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, and lead to Stored Cross-Site Scripting due to the lack of sanitisation and…

  • CVE-2022-1828MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1827MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2022-1826MedJun 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which could allow attackers to make a logged in admin perform such action via a CSRF attack