VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,623)

page 220 of 482
  • CVE-2024-4480MedJun 14, 2024
    risk 0.40cvss 6.1epss 0.00

    The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2024-4534MedMay 27, 2024
    risk 0.40cvss 6.1epss 0.00

    The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2024-3590MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers

  • CVE-2024-0613MedMay 2, 2024
    risk 0.40cvss 6.1epss 0.00

    The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3.1. This is due to missing or incorrect nonce validation on the ajax_delete_field() function. This makes it possible for unauthenticated attackers…

  • CVE-2024-3478MedMay 2, 2024
    risk 0.40cvss 6.1epss 0.00

    The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

  • CVE-2024-21044MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-21043MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-21032MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-21020MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-2857MedApr 15, 2024
    risk 0.40cvss 6.1epss 0.00

    The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it…

  • CVE-2022-45850MedMar 28, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro allows Stored XSS.This issue affects Image Map Pro: from n/a before 5.6.9.

  • CVE-2022-45847MedMar 27, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WPAssist.Me WordPress Countdown Widget allows Cross-Site Scripting (XSS).This issue affects WordPress Countdown Widget: from n/a through 3.1.9.1.

  • CVE-2024-29009MedMar 25, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication of the administrator and to perform unintended operations if the administrator views a malicious page while logged in.

  • CVE-2024-22475MedMar 18, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. allows a remote unauthenticated attacker to perform unintended operations on the affected product. As for the details of affected…

  • CVE-2024-28681MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/plus_edit.php.

  • CVE-2024-28677MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/article_keywords_main.php.

  • CVE-2024-28670MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_main.php.

  • CVE-2024-28667MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php

  • CVE-2024-28430MedMar 13, 2024
    risk 0.40cvss 6.1epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.

  • CVE-2023-52555MedMar 1, 2024
    risk 0.40cvss 6.1epss 0.00

    In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.