VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 280 of 482
  • CVE-2023-24428MedJan 26, 2023
    risk 0.30cvss 5.7epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.

  • CVE-2021-24968MedJan 24, 2022
    risk 0.30cvss 5.7epss 0.00

    The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ…

  • CVE-2021-32730MedJul 1, 2021
    risk 0.30cvss 5.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL that, when accessed by an…

  • CVE-2019-1632MedJun 20, 2019
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due…

  • CVE-2019-3410MedJun 11, 2019
    risk 0.30cvss 4.6epss 0.00

    All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requests come from trusted users. An attacker can exploit this…

  • CVE-2016-3004MedNov 30, 2016
    risk 0.30cvss 4.6epss 0.01

    Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the set of available applications.

  • CVE-2026-27146MedFeb 21, 2026
    risk 0.29cvss 4.5epss 0.00

    GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload request from an authenticated…

  • CVE-2026-25918MedFeb 9, 2026
    risk 0.29cvss 5.5epss 0.00

    unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are…

  • CVE-2025-55057MedNov 17, 2025
    risk 0.29cvss 4.5epss 0.00

    Multiple CWE-352 Cross-Site Request Forgery (CSRF)

  • CVE-2024-57523MedFeb 6, 2025
    risk 0.29cvss 4.5epss 0.00

    Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.

  • CVE-2024-13304MedJan 9, 2025
    risk 0.29cvss 4.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3.

  • CVE-2024-47914MedNov 14, 2024
    risk 0.29cvss 4.5epss 0.00

    VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)

  • CVE-2024-2405MedMay 2, 2024
    risk 0.29cvss 4.5epss 0.00

    The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

  • CVE-2024-27265MedMar 14, 2024
    risk 0.29cvss 4.5epss 0.00

    IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564.

  • CVE-2023-37598MedJul 13, 2023
    risk 0.29cvss 4.5epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.

  • CVE-2022-46062MedDec 13, 2022
    risk 0.29cvss 4.5epss 0.00

    Gym Management System v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).

  • CVE-2022-35656MedAug 22, 2022
    risk 0.29cvss 4.5epss 0.00

    Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.

  • CVE-2022-25576MedMar 24, 2022
    risk 0.29cvss 4.5epss 0.00

    Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.

  • CVE-2020-20586MedJul 8, 2021
    risk 0.29cvss 4.5epss 0.00

    A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and password.

  • CVE-2021-22701MedFeb 19, 2021
    risk 0.29cvss 4.5epss 0.00

    A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when…