VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 210 of 482
  • CVE-2005-2059MedJun 29, 2005
    risk 0.42cvss 6.5epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.

  • CVE-2026-39170MedJun 9, 2026
    risk 0.41cvss 6.3epss 0.00

    SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.

  • CVE-2026-30498MedMay 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.

  • CVE-2026-31014MedApr 21, 2026
    risk 0.41cvss 6.3epss 0.00

    Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing requests without requiring a CSRF token or equivalent protection. The endpoint accepts application/x-www-form-urlencoded requests, and…

  • CVE-2026-30868MedMar 11, 2026
    risk 0.41cvss 6.3epss 0.00

    OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but are accessible via HTTP GET requests without CSRF protection. The framework CSRF validation in ApiControllerBase only applies…

  • CVE-2025-54390MedSep 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureResetPasswordStatus attribute is enabled. An attacker can exploit this by tricking an authenticated user into visiting a malicious…

  • CVE-2025-36728MedJul 25, 2025
    risk 0.41cvss 6.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.

  • CVE-2025-30981MedJun 6, 2025
    risk 0.41cvss 6.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.26.14.

  • CVE-2025-46743MedMay 12, 2025
    risk 0.41cvss 6.3epss 0.00

    An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.

  • CVE-2025-29722MedApr 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.

  • CVE-2024-8243MedApr 9, 2025
    risk 0.41cvss 6.3epss 0.00

    The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

  • CVE-2025-23411MedFeb 13, 2025
    risk 0.41cvss 6.3epss 0.01

    mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.

  • CVE-2024-28141MedDec 11, 2024
    risk 0.41cvss 6.3epss 0.00

    The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an attacker-controlled website or click on a malicious link. E.g. an attacker can forge malicious…

  • CVE-2024-52392MedNov 19, 2024
    risk 0.41cvss 6.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in w3speedster W3SPEEDSTER w3speedster-wp.This issue affects W3SPEEDSTER: from n/a through <= 7.25.

  • CVE-2024-48291MedOct 28, 2024
    risk 0.41cvss 6.3epss 0.00

    dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17

  • CVE-2024-48191MedOct 28, 2024
    risk 0.41cvss 6.3epss 0.00

    dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17

  • CVE-2024-45983MedSep 26, 2024
    risk 0.41cvss 6.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability allows an attacker to craft a malicious HTML form that submits a request to delete a doctor record. By enticing an authenticated admin user to…

  • CVE-2024-46485MedSep 25, 2024
    risk 0.41cvss 6.3epss 0.00

    dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate

  • CVE-2024-6751MedJul 24, 2024
    risk 0.41cvss 6.3epss 0.00

    The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or…

  • CVE-2024-40328MedJul 10, 2024
    risk 0.41cvss 6.3epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.php?mudi=del&dataType=&dataID=6