CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 383 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24749 | Med | 0.28 | 4.3 | 0.00 | Nov 29, 2021 | The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack. | ||
| CVE-2021-24668 | Med | 0.28 | 4.3 | 0.00 | Nov 23, 2021 | The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack | ||
| CVE-2021-24853 | Med | 0.28 | 4.3 | 0.00 | Nov 17, 2021 | The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary… | ||
| CVE-2021-24776 | Med | 0.28 | 4.3 | 0.00 | Nov 17, 2021 | The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | ||
| CVE-2021-3776 | Med | 0.28 | 5.4 | 0.00 | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-3775 | Med | 0.28 | 5.4 | 0.00 | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-24832 | Med | 0.28 | 4.3 | 0.00 | Nov 8, 2021 | The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack | ||
| CVE-2021-24806 | Med | 0.28 | 4.3 | 0.00 | Nov 8, 2021 | The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers… | ||
| CVE-2021-24801 | Med | 0.28 | 4.3 | 0.00 | Nov 8, 2021 | The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to… | ||
| CVE-2021-24799 | Med | 0.28 | 4.3 | 0.00 | Nov 1, 2021 | The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | ||
| CVE-2021-24572 | Med | 0.28 | 4.3 | 0.00 | Nov 1, 2021 | The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result,… | ||
| CVE-2021-24570 | Med | 0.28 | 4.3 | 0.00 | Nov 1, 2021 | The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button.… | ||
| CVE-2015-10001 | Med | 0.28 | 4.3 | 0.00 | Nov 1, 2021 | The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads | ||
| CVE-2021-34743 | Med | 0.28 | 4.3 | 0.00 | Oct 21, 2021 | A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to… | ||
| CVE-2021-36877 | Med | 0.28 | 4.3 | 0.00 | Sep 27, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles. | ||
| CVE-2021-36878 | Med | 0.28 | 4.3 | 0.00 | Sep 27, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings. | ||
| CVE-2021-24583 | Med | 0.28 | 4.3 | 0.02 | Sep 20, 2021 | The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as… | ||
| CVE-2020-21321 | Med | 0.28 | 4.3 | 0.01 | Sep 15, 2021 | emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles. | ||
| CVE-2021-39124 | Med | 0.28 | 4.3 | 0.01 | Sep 14, 2021 | The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request. | ||
| CVE-2021-24725 | Med | 0.28 | 4.3 | 0.00 | Sep 13, 2021 | The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments |
- risk 0.28cvss 4.3epss 0.00
The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack.
- risk 0.28cvss 4.3epss 0.00
The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack
- risk 0.28cvss 4.3epss 0.00
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary…
- risk 0.28cvss 4.3epss 0.00
The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- risk 0.28cvss 5.4epss 0.00
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.28cvss 5.4epss 0.00
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.28cvss 4.3epss 0.00
The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could allow attackers to make a logged in admin delete them via a CSRF attack
- risk 0.28cvss 4.3epss 0.00
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers…
- risk 0.28cvss 4.3epss 0.00
The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sanitization in the Surveys' Title, this could also lead to…
- risk 0.28cvss 4.3epss 0.00
The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- risk 0.28cvss 4.3epss 0.00
The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result,…
- risk 0.28cvss 4.3epss 0.00
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button.…
- risk 0.28cvss 4.3epss 0.00
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
- risk 0.28cvss 4.3epss 0.00
A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to…
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.
- risk 0.28cvss 4.3epss 0.02
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as…
- risk 0.28cvss 4.3epss 0.01
emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.
- risk 0.28cvss 4.3epss 0.01
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.
- risk 0.28cvss 4.3epss 0.00
The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments