VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 264 of 482
  • CVE-2022-29414MedApr 29, 2022
    risk 0.35cvss 5.4epss 0.00

    Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key,…

  • CVE-2022-29412MedApr 28, 2022
    risk 0.35cvss 5.4epss 0.00

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete a source, create source.

  • CVE-2022-0398MedApr 25, 2022
    risk 0.35cvss 5.4epss 0.00

    The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to…

  • CVE-2022-1112MedApr 18, 2022
    risk 0.35cvss 5.4epss 0.00

    The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack

  • CVE-2022-27851MedApr 15, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API key.

  • CVE-2022-27850MedApr 15, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.

  • CVE-2022-25608MedMar 23, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into unwanted slider duplicate or delete action.

  • CVE-2022-25600MedMar 11, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).

  • CVE-2022-25599MedFeb 21, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).

  • CVE-2021-24446MedFeb 14, 2022
    risk 0.35cvss 5.4epss 0.00

    The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation

  • CVE-2020-13674MedFeb 11, 2022
    risk 0.35cvss 6.5epss 0.00

    The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is…

  • CVE-2022-0505MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.01

    Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2021-24993MedFeb 7, 2022
    risk 0.35cvss 6.5epss 0.00

    The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example

  • CVE-2021-44777MedJan 19, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions <= 5.2.6).

  • CVE-2022-0231MedJan 14, 2022
    risk 0.35cvss 6.5epss 0.01

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-23227MedJan 13, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions.

  • CVE-2021-24988MedDec 27, 2021
    risk 0.35cvss 5.4epss 0.00

    The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks,…

  • CVE-2021-4123MedDec 16, 2021
    risk 0.35cvss 6.5epss 0.00

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-4033MedDec 9, 2021
    risk 0.35cvss 6.5epss 0.01

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-4049MedDec 7, 2021
    risk 0.35cvss 6.5epss 0.00

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)