VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,622)

page 281 of 482
  • CVE-2020-36191MedJan 13, 2021
    risk 0.29cvss 4.5epss 0.01

    JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).

  • CVE-2020-13527MedDec 18, 2020
    risk 0.29cvss 4.5epss 0.01

    An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this…

  • CVE-2026-78280MedAug 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

  • CVE-2026-77391MedAug 21, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the…

  • CVE-2026-62671MedAug 19, 2026
    risk 0.28cvss 5.4epss 0.00

    Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level GET request through the TaskServiceProvider task: URI parameter without requiring a login-form nonce, an Origin…

  • CVE-2026-75151MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.

  • CVE-2026-73481MedAug 13, 2026
    risk 0.28cvss 5.4epss 0.00

    phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion is performed via a GET request (?page=bouncerules&del=N), and the central CSRF check (verifyCsrfGetToken) is invoked with…

  • CVE-2026-47229MedAug 12, 2026
    risk 0.28cvss 5.4epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `enable` case loads the SAML or OIDC client by UUID, calls `$client->enable($enabled)`, and…

  • CVE-2026-66775MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's…

  • CVE-2026-16965MedAug 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's…

  • CVE-2026-66681MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.

  • CVE-2026-70556MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications under an authenticated user's…

  • CVE-2026-17515MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS…

  • CVE-2026-16613MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a…

  • CVE-2026-18819MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2025-14469MedAug 1, 2026
    risk 0.28cvss 4.3epss 0.00

    The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1. This is due to missing nonce validation on the ms_update AJAX action. This makes it possible for unauthenticated attackers to modify child theme CSS…

  • CVE-2026-13729MedAug 1, 2026
    risk 0.28cvss 4.3epss 0.00

    The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator…

  • CVE-2026-49215MedJul 17, 2026
    risk 0.28cvss 5.4epss 0.00

    Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest() gates #[LiveAction] invocations on Accept: application/vnd.live-component+html, but the Accept header is…

  • CVE-2026-13952MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-13946MedJun 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)