CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,622)
page 280 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24428 | Med | 0.30 | 5.7 | 0.00 | Jan 26, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account. | ||
| CVE-2021-24968 | Med | 0.30 | 5.7 | 0.00 | Jan 24, 2022 | The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ… | ||
| CVE-2021-32730 | Med | 0.30 | 5.7 | 0.01 | Jul 1, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL that, when accessed by an… | ||
| CVE-2019-1632 | Med | 0.30 | 4.6 | 0.00 | Jun 20, 2019 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due… | ||
| CVE-2019-3410 | Med | 0.30 | 4.6 | 0.00 | Jun 11, 2019 | All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requests come from trusted users. An attacker can exploit this… | ||
| CVE-2016-3004 | Med | 0.30 | 4.6 | 0.01 | Nov 30, 2016 | Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the set of available applications. | ||
| CVE-2026-27146 | Med | 0.29 | 4.5 | 0.00 | Feb 21, 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload request from an authenticated… | ||
| CVE-2026-25918 | Med | 0.29 | 5.5 | 0.00 | Feb 9, 2026 | unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are… | ||
| CVE-2025-55057 | Med | 0.29 | 4.5 | 0.00 | Nov 17, 2025 | Multiple CWE-352 Cross-Site Request Forgery (CSRF) | ||
| CVE-2024-57523 | Med | 0.29 | 4.5 | 0.00 | Feb 6, 2025 | Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user. | ||
| CVE-2024-13304 | Med | 0.29 | 4.5 | 0.00 | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3. | ||
| CVE-2024-47914 | — | Med | 0.29 | 4.5 | 0.00 | Nov 14, 2024 | VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF) | |
| CVE-2024-2405 | Med | 0.29 | 4.5 | 0.00 | May 2, 2024 | The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack. | ||
| CVE-2024-27265 | Med | 0.29 | 4.5 | 0.00 | Mar 14, 2024 | IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564. | ||
| CVE-2023-37598 | Med | 0.29 | 4.5 | 0.01 | Jul 13, 2023 | A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function. | ||
| CVE-2022-46062 | Med | 0.29 | 4.5 | 0.00 | Dec 13, 2022 | Gym Management System v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF). | ||
| CVE-2022-35656 | Med | 0.29 | 4.5 | 0.00 | Aug 22, 2022 | Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly. | ||
| CVE-2022-25576 | Med | 0.29 | 4.5 | 0.00 | Mar 24, 2022 | Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts. | ||
| CVE-2020-20586 | Med | 0.29 | 4.5 | 0.00 | Jul 8, 2021 | A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and password. | ||
| CVE-2021-22701 | Med | 0.29 | 4.5 | 0.00 | Feb 19, 2021 | A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when… |
- risk 0.30cvss 5.7epss 0.00
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.
- risk 0.30cvss 5.7epss 0.00
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ…
- risk 0.30cvss 5.7epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL that, when accessed by an…
- risk 0.30cvss 4.6epss 0.00
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due…
- risk 0.30cvss 4.6epss 0.00
All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery vulnerability,which stems from the fact that WEB applications do not adequately verify whether requests come from trusted users. An attacker can exploit this…
- risk 0.30cvss 4.6epss 0.01
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the set of available applications.
- risk 0.29cvss 4.5epss 0.00
GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload request from an authenticated…
- risk 0.29cvss 5.5epss 0.00
unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are…
- risk 0.29cvss 4.5epss 0.00
Multiple CWE-352 Cross-Site Request Forgery (CSRF)
- risk 0.29cvss 4.5epss 0.00
Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.
- risk 0.29cvss 4.5epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3.
- risk 0.29cvss 4.5epss 0.00
VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)
- risk 0.29cvss 4.5epss 0.00
The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.
- risk 0.29cvss 4.5epss 0.00
IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 284564.
- risk 0.29cvss 4.5epss 0.01
A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.
- risk 0.29cvss 4.5epss 0.00
Gym Management System v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
- risk 0.29cvss 4.5epss 0.00
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
- risk 0.29cvss 4.5epss 0.00
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.php. This vulnerability allows attackers to arbitrarily delete posts.
- risk 0.29cvss 4.5epss 0.00
A cross site request forgery (CSRF) vulnerability in the /xyhai.php?s=/Auth/editUser URI of XYHCMS V3.6 allows attackers to edit any information of the administrator such as the name, e-mail, and password.
- risk 0.29cvss 4.5epss 0.00
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when…