VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 225 of 482
  • CVE-2026-26317HigFeb 19, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prevent browser-initiated requests from…

  • CVE-2025-58690HigSep 22, 2025
    risk 0.39cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect doliconnect allows Stored XSS.This issue affects Doliconnect: from n/a through <= 9.5.7.

  • CVE-2025-1473HigMar 20, 2025
    risk 0.39cvss 7.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.

  • CVE-2024-37213HigJul 12, 2024
    risk 0.39cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in guru-aliexpress AliNext ali2woo-lite allows Cross Site Request Forgery.This issue affects AliNext: from n/a through <= 3.4.6.

  • CVE-2024-34818HigMay 14, 2024
    risk 0.39cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.

  • CVE-2024-27631MedApr 8, 2024
    risk 0.39cvss 6.0epss 0.00

    Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

  • CVE-2024-0428HigFeb 5, 2024
    risk 0.39cvss 7.1epss 0.00

    The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing or incorrect nonce validation on the 'reset_form' function. This makes it possible for unauthenticated attackers to delete arbitrary…

  • CVE-2021-25108HigFeb 7, 2022
    risk 0.39cvss 7.1epss 0.00

    The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing…

  • CVE-2021-25095HigFeb 7, 2022
    risk 0.39cvss 7.1epss 0.01

    The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them…

  • CVE-2022-20619HigJan 12, 2022
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…

  • CVE-2021-21655HigMay 11, 2021
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.

  • CVE-2019-12922MedSep 13, 2019
    risk 0.39cvss 6.5epss 0.10

    A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

  • CVE-2019-1003044HigMar 28, 2019
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2017-0045MedMar 17, 2017
    risk 0.39cvss 5.5epss 0.07

    Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery…

  • CVE-2026-76549MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could allow attackers to make a logged in admin restore an existing backup, reverting the site's database and files to an earlier…

  • CVE-2026-63654MedAug 20, 2026
    risk 0.38cvss epss 0.00

    Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because the endpoint is not…

  • CVE-2026-47725MedJul 28, 2026
    risk 0.38cvss epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DELETE route processes the request as soon as the session cookie validates. SameSite=Lax on the session cookie prevents most…

  • CVE-2026-58482MedJul 20, 2026
    risk 0.38cvss 5.9epss 0.00

    Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which `ApprovalGate` uses to require explicit human approval…

  • CVE-2026-9591MedJun 17, 2026
    risk 0.38cvss epss 0.00

    Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an administrator via a crafted form submitted to `/api/news-items`, due to missing anti-CSRF…

  • CVE-2025-48740MedMay 23, 2025
    risk 0.38cvss epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows a remote attacker to trigger requests on their victim's behalf, if the attacker lures a privileged user,…