VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 228 of 482
  • CVE-2023-7229MedMay 15, 2025
    risk 0.36cvss 5.5epss 0.00

    The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

  • CVE-2025-25873MedMar 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function

  • CVE-2024-44293MedDec 20, 2024
    risk 0.36cvss 5.5epss 0.00

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to view sensitive user information.

  • CVE-2024-48278MedOct 15, 2024
    risk 0.36cvss 5.5epss 0.00

    Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.

  • CVE-2024-5285MedJul 29, 2024
    risk 0.36cvss 5.5epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

  • CVE-2024-35557MedMay 22, 2024
    risk 0.36cvss 5.5epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.

  • CVE-2024-3824MedMay 15, 2024
    risk 0.36cvss 5.5epss 0.00

    The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

  • CVE-2024-30946MedApr 2, 2024
    risk 0.36cvss 5.5epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.

  • CVE-2024-28666MedMar 13, 2024
    risk 0.36cvss 5.5epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/media_add.php

  • CVE-2024-28429MedMar 13, 2024
    risk 0.36cvss 5.5epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php

  • CVE-2023-48258MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.00

    The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.

  • CVE-2023-42435MedOct 19, 2023
    risk 0.36cvss 5.5epss 0.00

    The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to perform actions with the permissions of a victim user.

  • CVE-2022-38059MedSep 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Alexey Trofimov's Access Code Feeder plugin <= 1.0.3 at WordPress.

  • CVE-2013-4792MedFeb 14, 2020
    risk 0.36cvss 5.5epss 0.00

    PrestaShop before 1.4.11 allows logout CSRF.

  • CVE-2026-48549MedAug 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST body, allowing a cross-site…

  • CVE-2026-48548MedAug 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST request to execute arbitrary Nagios commands as a…

  • CVE-2026-78279MedAug 24, 2026
    risk 0.35cvss 5.4epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.

  • CVE-2026-57944MedAug 22, 2026
    risk 0.35cvss 5.4epss 0.00

    AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying…

  • CVE-2026-63123MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugi…

  • CVE-2026-71123MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…