CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,622)
page 265 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3993 | Med | 0.35 | 6.5 | 0.01 | Dec 1, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-24822 | Med | 0.35 | 5.4 | 0.00 | Nov 29, 2021 | The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site… | ||
| CVE-2021-3976 | Med | 0.35 | 6.5 | 0.00 | Nov 19, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-3683 | Med | 0.35 | 6.5 | 0.00 | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-24685 | Med | 0.35 | 5.4 | 0.01 | Nov 1, 2021 | The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the… | ||
| CVE-2021-3900 | Med | 0.35 | 6.5 | 0.01 | Oct 27, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-24615 | Med | 0.35 | 5.4 | 0.00 | Oct 18, 2021 | The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks. | ||
| CVE-2021-24683 | Med | 0.35 | 5.4 | 0.00 | Oct 11, 2021 | The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue. | ||
| CVE-2021-36850 | Med | 0.35 | 5.4 | 0.00 | Oct 4, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state. | ||
| CVE-2021-36876 | Med | 0.35 | 5.4 | 0.00 | Sep 27, 2021 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages. | ||
| CVE-2021-22953 | Med | 0.35 | 5.4 | 0.00 | Sep 23, 2021 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team" | ||
| CVE-2021-22949 | Med | 0.35 | 5.4 | 0.00 | Sep 23, 2021 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team" | ||
| CVE-2021-24618 | Med | 0.35 | 5.4 | 0.00 | Sep 20, 2021 | The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing… | ||
| CVE-2021-24584 | Med | 0.35 | 5.4 | 0.01 | Sep 20, 2021 | The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot from any events. Furthermore, no CSRF check is in place as… | ||
| CVE-2021-24611 | Med | 0.35 | 5.4 | 0.00 | Sep 6, 2021 | The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in… | ||
| CVE-2021-3730 | Med | 0.35 | 6.5 | 0.00 | Aug 23, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-3728 | Med | 0.35 | 6.5 | 0.01 | Aug 23, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2020-18151 | Med | 0.35 | 6.5 | 0.00 | Jul 14, 2021 | Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account. | ||
| CVE-2021-24388 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2021 | In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving the order. However, the field name is not sanitised or escaped before being output… | ||
| CVE-2021-28055 | Med | 0.35 | 6.5 | 0.01 | Apr 15, 2021 | An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user. |
- risk 0.35cvss 6.5epss 0.01
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 5.4epss 0.00
The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to authenticated users), which could allow any authenticated users, such as subscriber to call them, and perform Stored Cross-Site…
- risk 0.35cvss 6.5epss 0.00
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 6.5epss 0.00
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 5.4epss 0.01
The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them, which could allow attackers to a make logged in admin change them with a Cross-Site Scripting payload (triggered either in the…
- risk 0.35cvss 6.5epss 0.01
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 5.4epss 0.00
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.
- risk 0.35cvss 5.4epss 0.00
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.
- risk 0.35cvss 5.4epss 0.00
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.
- risk 0.35cvss 5.4epss 0.00
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"
- risk 0.35cvss 5.4epss 0.00
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"
- risk 0.35cvss 5.4epss 0.00
The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing…
- risk 0.35cvss 5.4epss 0.01
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a timeslot, allowing any user with the edit_posts capability (contributor+) to update arbitrary timeslot from any events. Furthermore, no CSRF check is in place as…
- risk 0.35cvss 5.4epss 0.00
The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in…
- risk 0.35cvss 6.5epss 0.00
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 6.5epss 0.01
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.35cvss 6.5epss 0.00
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.
- risk 0.35cvss 5.4epss 0.00
In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving the order. However, the field name is not sanitised or escaped before being output…
- risk 0.35cvss 6.5epss 0.01
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.