VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 277 of 482
  • CVE-2024-3582MedMay 14, 2024
    risk 0.31cvss 4.8epss 0.00

    The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

  • CVE-2024-2858MedApr 15, 2024
    risk 0.31cvss 4.8epss 0.00

    The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

  • CVE-2024-2262MedApr 1, 2024
    risk 0.31cvss 4.7epss 0.00

    Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

  • CVE-2024-1232MedMar 25, 2024
    risk 0.31cvss 4.8epss 0.00

    The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack

  • CVE-2024-1501MedFeb 21, 2024
    risk 0.31cvss 4.7epss 0.00

    The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the…

  • CVE-2021-25117MedJan 16, 2024
    risk 0.31cvss 4.8epss 0.00

    The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). Even though the page is only accessible to administrators, and protected against CSRF…

  • CVE-2022-45079MedMay 22, 2023
    risk 0.31cvss 4.7epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.

  • CVE-2022-4944MedApr 22, 2023
    risk 0.31cvss 4.3epss 0.03

    A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been…

  • CVE-2022-27628MedFeb 6, 2023
    risk 0.31cvss 4.7epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions.

  • CVE-2022-47131MedFeb 3, 2023
    risk 0.31cvss 4.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.

  • CVE-2022-41413MedNov 30, 2022
    risk 0.31cvss 4.3epss 0.02

    perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.

  • CVE-2022-3750MedNov 21, 2022
    risk 0.31cvss 4.7epss 0.00

    The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.

  • CVE-2022-2846MedAug 16, 2022
    risk 0.31cvss 4.3epss 0.03

    The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create…

  • CVE-2022-35943MedAug 12, 2022
    risk 0.31cvss 5.9epss 0.01

    Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/libraries/security.html)…

  • CVE-2022-29430MedMay 20, 2022
    risk 0.31cvss 4.7epss 0.00

    Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter &jpg_quality.

  • CVE-2022-29436MedMay 17, 2022
    risk 0.31cvss 4.7epss 0.00

    Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code).

  • CVE-2022-29413MedApr 28, 2022
    risk 0.31cvss 4.7epss 0.00

    Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title parameter.

  • CVE-2022-0328MedFeb 28, 2022
    risk 0.31cvss 4.7epss 0.00

    The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

  • CVE-2021-46080MedJan 6, 2022
    risk 0.31cvss 4.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads to Stored Cross Site Scripting Vulnerability.

  • CVE-2021-24272MedMay 5, 2021
    risk 0.31cvss 4.3epss 0.02

    The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the…