CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,622)
page 264 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29414 | Med | 0.35 | 5.4 | 0.00 | Apr 29, 2022 | Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key,… | ||
| CVE-2022-29412 | Med | 0.35 | 5.4 | 0.00 | Apr 28, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete a source, create source. | ||
| CVE-2022-0398 | Med | 0.35 | 5.4 | 0.00 | Apr 25, 2022 | The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to… | ||
| CVE-2022-1112 | Med | 0.35 | 5.4 | 0.00 | Apr 18, 2022 | The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack | ||
| CVE-2022-27851 | Med | 0.35 | 5.4 | 0.00 | Apr 15, 2022 | Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API key. | ||
| CVE-2022-27850 | Med | 0.35 | 5.4 | 0.00 | Apr 15, 2022 | Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message. | ||
| CVE-2022-25608 | Med | 0.35 | 5.4 | 0.00 | Mar 23, 2022 | Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into unwanted slider duplicate or delete action. | ||
| CVE-2022-25600 | Med | 0.35 | 5.4 | 0.01 | Mar 11, 2022 | Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3). | ||
| CVE-2022-25599 | Med | 0.35 | 5.4 | 0.00 | Feb 21, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0). | ||
| CVE-2021-24446 | Med | 0.35 | 5.4 | 0.00 | Feb 14, 2022 | The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation | ||
| CVE-2020-13674 | Med | 0.35 | 6.5 | 0.00 | Feb 11, 2022 | The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is… | ||
| CVE-2022-0505 | Med | 0.35 | 6.5 | 0.01 | Feb 8, 2022 | Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. | ||
| CVE-2021-24993 | Med | 0.35 | 6.5 | 0.00 | Feb 7, 2022 | The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example | ||
| CVE-2021-44777 | Med | 0.35 | 5.4 | 0.00 | Jan 19, 2022 | Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions <= 5.2.6). | ||
| CVE-2022-0231 | Med | 0.35 | 6.5 | 0.01 | Jan 14, 2022 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-23227 | Med | 0.35 | 5.4 | 0.00 | Jan 13, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions. | ||
| CVE-2021-24988 | Med | 0.35 | 5.4 | 0.00 | Dec 27, 2021 | The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks,… | ||
| CVE-2021-4123 | Med | 0.35 | 6.5 | 0.00 | Dec 16, 2021 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-4033 | Med | 0.35 | 6.5 | 0.01 | Dec 9, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-4049 | Med | 0.35 | 6.5 | 0.00 | Dec 7, 2021 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
- risk 0.35cvss 5.4epss 0.00
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key,…
- risk 0.35cvss 5.4epss 0.00
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete a source, create source.
- risk 0.35cvss 5.4epss 0.00
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which could then be used to…
- risk 0.35cvss 5.4epss 0.00
The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API key.
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into unwanted slider duplicate or delete action.
- risk 0.35cvss 5.4epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).
- risk 0.35cvss 5.4epss 0.00
The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation
- risk 0.35cvss 6.5epss 0.00
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affected if the QuickEdit module (which comes with the Standard profile) is…
- risk 0.35cvss 6.5epss 0.01
Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
- risk 0.35cvss 6.5epss 0.00
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions <= 5.2.6).
- risk 0.35cvss 6.5epss 0.01
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions.
- risk 0.35cvss 5.4epss 0.00
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks,…
- risk 0.35cvss 6.5epss 0.00
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 6.5epss 0.01
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 6.5epss 0.00
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)