VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 265 of 482
  • CVE-2021-3993MedDec 1, 2021
    risk 0.35cvss 6.5epss 0.01

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-24822MedNov 29, 2021
    risk 0.35cvss 5.4epss 0.00

    The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site…

  • CVE-2021-3976MedNov 19, 2021
    risk 0.35cvss 6.5epss 0.00

    kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3683MedNov 13, 2021
    risk 0.35cvss 6.5epss 0.00

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-24685MedNov 1, 2021
    risk 0.35cvss 5.4epss 0.01

    The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the…

  • CVE-2021-3900MedOct 27, 2021
    risk 0.35cvss 6.5epss 0.01

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-24615MedOct 18, 2021
    risk 0.35cvss 5.4epss 0.00

    The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.

  • CVE-2021-24683MedOct 11, 2021
    risk 0.35cvss 5.4epss 0.00

    The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.

  • CVE-2021-36850MedOct 4, 2021
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.

  • CVE-2021-36876MedSep 27, 2021
    risk 0.35cvss 5.4epss 0.00

    Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.

  • CVE-2021-22953MedSep 23, 2021
    risk 0.35cvss 5.4epss 0.00

    A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"

  • CVE-2021-22949MedSep 23, 2021
    risk 0.35cvss 5.4epss 0.00

    A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"

  • CVE-2021-24618MedSep 20, 2021
    risk 0.35cvss 5.4epss 0.00

    The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing…

  • CVE-2021-24584MedSep 20, 2021
    risk 0.35cvss 5.4epss 0.01

    The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot from any events. Furthermore, no CSRF check is in place as…

  • CVE-2021-24611MedSep 6, 2021
    risk 0.35cvss 5.4epss 0.00

    The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in…

  • CVE-2021-3730MedAug 23, 2021
    risk 0.35cvss 6.5epss 0.00

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3728MedAug 23, 2021
    risk 0.35cvss 6.5epss 0.01

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2020-18151MedJul 14, 2021
    risk 0.35cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.

  • CVE-2021-24388MedJul 6, 2021
    risk 0.35cvss 5.4epss 0.00

    In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving the order. However, the field name is not sanitised or escaped before being output…

  • CVE-2021-28055MedApr 15, 2021
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.