VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 276 of 482
  • CVE-2025-68481MedDec 19, 2025
    risk 0.31cvss 5.9epss 0.00

    FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that…

  • CVE-2025-48099MedOct 22, 2025
    risk 0.31cvss 4.7epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forgery.This issue affects Search & Filter: from n/a through <= 1.2.17.

  • CVE-2025-28355MedApr 18, 2025
    risk 0.31cvss 4.7epss 0.00

    Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none

  • CVE-2025-24387MedMar 10, 2025
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read…

  • CVE-2025-0522MedFeb 6, 2025
    risk 0.31cvss 4.7epss 0.00

    The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

  • CVE-2024-12955MedDec 26, 2024
    risk 0.31cvss 4.3epss 0.01

    A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic. This vulnerability affects unknown code of the file /logout.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The…

  • CVE-2024-56140MedDec 18, 2024
    risk 0.31cvss 5.9epss 0.00

    Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF checks. When the `security.checkOrigin` configuration option is set to `true`, Astro middleware will perform a CSRF check.…

  • CVE-2024-5029MedNov 21, 2024
    risk 0.31cvss 4.8epss 0.00

    The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

  • CVE-2024-51156MedNov 14, 2024
    risk 0.31cvss 4.7epss 0.00

    07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.

  • CVE-2021-27701MedNov 12, 2024
    risk 0.31cvss 4.7epss 0.00

    SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a CSRF token and request validation. An attacker can Add/Modify any random user data by sending a crafted CSRF request.

  • CVE-2024-51157MedNov 8, 2024
    risk 0.31cvss 4.7epss 0.00

    07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.

  • CVE-2024-48913MedOct 15, 2024
    risk 0.31cvss 5.9epss 0.00

    Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type…

  • CVE-2024-46911MedOct 14, 2024
    risk 0.31cvss 4.7epss 0.00

    Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF protections allowed an…

  • CVE-2024-46600MedSep 25, 2024
    risk 0.31cvss 4.7epss 0.00

    dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31

  • CVE-2023-1604MedAug 17, 2024
    risk 0.31cvss 4.7epss 0.00

    The Short URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.8. This is due to missing or incorrect nonce validation on the configuration_page function. This makes it possible for unauthenticated attackers to add and import…

  • CVE-2024-7420MedAug 15, 2024
    risk 0.31cvss 5.8epss 0.00

    The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation in the /admin/snippets.php file. This makes it possible for unauthenticated attackers to…

  • CVE-2024-41305MedJul 30, 2024
    risk 0.31cvss 4.7epss 0.00

    A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

  • CVE-2024-5280MedJul 13, 2024
    risk 0.31cvss 4.7epss 0.00

    The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack

  • CVE-2024-39153MedJun 27, 2024
    risk 0.31cvss 4.7epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/info_deal.php?mudi=del&dataType=news&dataTypeCN.

  • CVE-2024-3941MedMay 14, 2024
    risk 0.31cvss 4.7epss 0.00

    The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.