VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 278 of 482
  • CVE-2020-28482MedJan 19, 2021
    risk 0.31cvss 5.9epss 0.01

    This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts: { path: '/', sameSite: true } 2. The CSRF token was available in the GET query parameter

  • CVE-2020-35687MedJan 13, 2021
    risk 0.31cvss 4.3epss 0.01

    PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

  • CVE-2020-4651MedNov 9, 2020
    risk 0.31cvss 4.8epss 0.00

    IBM Maximo Spatial Asset Management 7.6.0.3, 7.6.0.4, 7.6.0.5, and 7.6.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186024.

  • CVE-2020-11003MedApr 14, 2020
    risk 0.31cvss 4.8epss 0.01

    Oasis before version 2.15.0 has a potential DNS rebinding or CSRF vulnerability. If you're running a vulnerable application on your computer and an attacker can trick you into visiting a malicious website, they could use DNS rebinding and CSRF attacks to read/write to vulnerable…

  • CVE-2019-20100MedFeb 12, 2020
    risk 0.31cvss 4.7epss 0.01

    The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are affected: all versions prior to 5.4.21, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 before version…

  • CVE-2019-1881MedJun 5, 2019
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to…

  • CVE-2019-3604MedFeb 1, 2019
    risk 0.31cvss 4.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vectors.

  • CVE-2019-1658MedJan 24, 2019
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to…

  • CVE-2017-16653MedAug 6, 2018
    risk 0.31cvss 5.9epss 0.01

    An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subject to MITM attacks on HTTP and…

  • CVE-2018-11448MedJun 26, 2018
    risk 0.31cvss 4.8epss 0.00

    A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a stored Cross-Site Scripting (XSS) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires that the attacker…

  • CVE-2016-8018MedMar 14, 2017
    risk 0.31cvss 4.3epss 0.03

    Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to execute unauthorized commands via a crafted user input.

  • CVE-2026-77029MedAug 21, 2026
    risk 0.30cvss epss 0.00

    Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66

  • CVE-2026-75952MedAug 19, 2026
    risk 0.30cvss epss 0.00

    Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install,…

  • CVE-2022-44630MedJun 11, 2026
    risk 0.30cvss 4.6epss 0.00

    Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery. This issue affects YITH WooCommerce Product Slider Carousel: from n/a through 1.16.0.

  • CVE-2026-32816MedMar 19, 2026
    risk 0.30cvss 5.7epss 0.00

    Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-roles/groups_roles.php perform destructive state changes on organizational roles but never validate an anti-CSRF token. The…

  • CVE-2026-32755MedMar 19, 2026
    risk 0.30cvss 5.7epss 0.00

    Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php saves changes to a member's role membership start and end dates but does not validate the CSRF token. The handler checks…

  • CVE-2026-29084MedMar 6, 2026
    risk 0.30cvss 4.6epss 0.00

    Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the login flow accepts credential-bearing requests without CSRF protection mechanisms tied to the browser session context. The handler parses form values…

  • CVE-2026-24007MedFeb 2, 2026
    risk 0.30cvss 4.6epss 0.00

    Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links…

  • CVE-2025-68158MedJan 8, 2026
    risk 0.30cvss 5.7epss 0.00

    Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that has a valid state (easily obtainable via an…

  • CVE-2025-65962MedDec 9, 2025
    risk 0.30cvss 4.6epss 0.00

    Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Community Edition prior to 17.0.99.1763803709 and Tuleap Enterprise Edition versions prior to 17.0-4 and 16.13-9 are mission CSRF protections in its tracker field…