VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 272 of 482
  • CVE-2023-26840MedApr 25, 2023
    risk 0.34cvss 5.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administrator.

  • CVE-2022-43980MedJan 27, 2023
    risk 0.34cvss 5.2epss 0.00

    There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a network map, including on purpose the name of an XSS payload. Once created, if a user with admin privileges clicks on the edited network…

  • CVE-2022-3489MedNov 7, 2022
    risk 0.34cvss 5.3epss 0.00

    The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allowing unauthenticated attackers to update it with a crafted request

  • CVE-2022-40180MedOct 11, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions <…

  • CVE-2022-2350MedOct 10, 2022
    risk 0.34cvss 5.3epss 0.00

    The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will.

  • CVE-2022-2783MedOct 6, 2022
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token

  • CVE-2017-20020MedJun 9, 2022
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown functionality. The manipulation leads to cross site request forgery. The attack may be launched remotely. Upgrading to version…

  • CVE-2021-34360MedMay 26, 2022
    risk 0.34cvss 5.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server:…

  • CVE-2021-24978MedMar 28, 2022
    risk 0.34cvss 5.3epss 0.01

    The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and is registered with the wp_ajax_nopriv prefix, making it available to unauthenticated users. There is no authorisation, CSRF and checks in place to ensure that…

  • CVE-2021-39197MedSep 7, 2021
    risk 0.34cvss 6.3epss 0.01

    better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It is also usable outside of Rails in any Rack app as Rack middleware. better_errors prior to 2.8.0 did not implement CSRF protection for its internal requests.…

  • CVE-2020-28452MedJan 20, 2021
    risk 0.34cvss 6.3epss 0.01

    This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package com.softwaremill.akka-http-session:core_2.11; the package com.softwaremill.akka-http-session:core_2.13 from 0 and before 0.6.1. CSRF protection can be bypassed…

  • CVE-2020-7780MedNov 27, 2020
    risk 0.34cvss 6.3epss 0.01

    This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by…

  • CVE-2020-9018MedFeb 25, 2020
    risk 0.34cvss 5.3epss 0.00

    LiteCart through 2.2.1 allows admin/?app=users&doc=edit_user CSRF to add a user.

  • CVE-2019-19375MedNov 28, 2019
    risk 0.34cvss 5.3epss 0.00

    In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)

  • CVE-2019-10359MedJul 31, 2019
    risk 0.34cvss 6.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.

  • CVE-2018-19335MedNov 20, 2018
    risk 0.34cvss 5.3epss 0.00

    Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug…

  • CVE-2018-19334MedNov 20, 2018
    risk 0.34cvss 5.3epss 0.00

    Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.

  • CVE-2018-10099MedNov 20, 2018
    risk 0.34cvss 5.3epss 0.00

    Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.

  • CVE-2026-81733MedAug 28, 2026
    risk 0.33cvss epss

    WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from…

  • CVE-2026-64962MedAug 20, 2026
    risk 0.33cvss epss 0.00

    ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visited by an authenticated victim, submits a forged request to the system. Due to the lack of proper CSRF token implementation, the…