VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 227 of 482
  • CVE-2023-47870MedNov 30, 2023
    risk 0.37cvss 5.7epss 0.00

    Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a…

  • CVE-2023-31200MedJun 7, 2023
    risk 0.37cvss 5.7epss 0.00

    PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a replay attack.

  • CVE-2023-2228MedApr 21, 2023
    risk 0.37cvss 6.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.

  • CVE-2022-3881MedDec 12, 2022
    risk 0.37cvss 5.7epss 0.00

    The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log WordPress plugin before 3.43 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it…

  • CVE-2022-37043MedAug 12, 2022
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth, CSRF tokens are not checked on some POST endpoints. Thus, when an authenticated user views an attacker-controlled page, a request will be sent to the…

  • CVE-2022-20787MedApr 21, 2022
    risk 0.37cvss 5.7epss 0.00

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack…

  • CVE-2021-25011MedFeb 28, 2022
    risk 0.37cvss 5.7epss 0.00

    The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

  • CVE-2021-3944MedDec 2, 2021
    risk 0.37cvss 6.8epss 0.01

    bookstack is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-24703MedNov 23, 2021
    risk 0.37cvss 5.7epss 0.00

    The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

  • CVE-2021-24752MedOct 18, 2021
    risk 0.37cvss 5.7epss 0.00

    Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3,…

  • CVE-2020-19268MedSep 9, 2021
    risk 0.37cvss 5.7epss 0.00

    A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.

  • CVE-2020-18124MedAug 30, 2021
    risk 0.37cvss 5.7epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.

  • CVE-2020-15156MedAug 26, 2020
    risk 0.37cvss 6.8epss 0.01

    In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF validation.

  • CVE-2020-12781MedAug 10, 2020
    risk 0.37cvss 5.7epss 0.00

    Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.

  • CVE-2019-14683MedAug 8, 2019
    risk 0.37cvss 5.7epss 0.01

    The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSRF.

  • CVE-2019-14680MedAug 8, 2019
    risk 0.37cvss 5.7epss 0.01

    The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.

  • CVE-2019-8902MedFeb 18, 2019
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.

  • CVE-2019-7730MedFeb 11, 2019
    risk 0.37cvss 5.7epss 0.00

    MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.

  • CVE-2025-51733MedNov 28, 2025
    risk 0.36cvss 5.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0.

  • CVE-2025-43296MedOct 9, 2025
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.