CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,623)
page 204 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-9424 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter. | ||
| CVE-2015-9422 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters. | ||
| CVE-2015-9421 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter. | ||
| CVE-2015-9417 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS. | ||
| CVE-2015-9413 | Med | 0.42 | 6.5 | 0.01 | Sep 26, 2019 | The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter. | ||
| CVE-2015-9409 | Med | 0.42 | 6.5 | 0.01 | Sep 25, 2019 | The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php. | ||
| CVE-2019-4515 | Med | 0.42 | 6.5 | 0.01 | Sep 24, 2019 | IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 165137. | ||
| CVE-2019-16721 | Med | 0.42 | 6.5 | 0.01 | Sep 23, 2019 | NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user. | ||
| CVE-2019-16719 | Med | 0.42 | 6.5 | 0.01 | Sep 23, 2019 | WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS. | ||
| CVE-2019-16678 | Med | 0.42 | 6.5 | 0.01 | Sep 21, 2019 | admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route. | ||
| CVE-2019-16677 | Med | 0.42 | 6.5 | 0.00 | Sep 21, 2019 | An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF. | ||
| CVE-2018-17789 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2019 | Prospecta Master Data Online (MDO) allows CSRF. | ||
| CVE-2015-9408 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2019 | The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS. | ||
| CVE-2016-10997 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2019 | The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php. | ||
| CVE-2015-9388 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. | ||
| CVE-2015-9387 | Med | 0.42 | 6.5 | 0.01 | Sep 20, 2019 | The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. | ||
| CVE-2016-10962 | Med | 0.42 | 6.5 | 0.01 | Sep 16, 2019 | The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter. | ||
| CVE-2016-10938 | Med | 0.42 | 6.5 | 0.01 | Sep 13, 2019 | The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location. | ||
| CVE-2019-14998 | Med | 0.42 | 6.5 | 0.01 | Sep 11, 2019 | The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance. | ||
| CVE-2019-10253 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2019 | A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists… |
- risk 0.42cvss 6.5epss 0.01
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
- risk 0.42cvss 6.5epss 0.01
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters.
- risk 0.42cvss 6.5epss 0.01
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
- risk 0.42cvss 6.5epss 0.01
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
- risk 0.42cvss 6.5epss 0.01
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
- risk 0.42cvss 6.5epss 0.01
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
- risk 0.42cvss 6.5epss 0.01
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 165137.
- risk 0.42cvss 6.5epss 0.01
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
- risk 0.42cvss 6.5epss 0.01
WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.
- risk 0.42cvss 6.5epss 0.01
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
- risk 0.42cvss 6.5epss 0.00
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
- risk 0.42cvss 6.5epss 0.01
Prospecta Master Data Online (MDO) allows CSRF.
- risk 0.42cvss 6.5epss 0.01
The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.
- risk 0.42cvss 6.5epss 0.01
The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.
- risk 0.42cvss 6.5epss 0.01
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.
- risk 0.42cvss 6.5epss 0.01
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.
- risk 0.42cvss 6.5epss 0.01
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
- risk 0.42cvss 6.5epss 0.01
The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
- risk 0.42cvss 6.5epss 0.01
The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its protection via "cookie tossing" a CSRF cookie from a subdomain of a Jira instance.
- risk 0.42cvss 6.5epss 0.01
A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists…