CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 384 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24586 | Med | 0.28 | 4.3 | 0.00 | Sep 13, 2021 | The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned… | ||
| CVE-2021-24431 | Med | 0.28 | 4.3 | 0.00 | Sep 13, 2021 | The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set… | ||
| CVE-2021-27557 | Med | 0.28 | 4.3 | 0.00 | Aug 31, 2021 | A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job. | ||
| CVE-2021-32991 | Med | 0.28 | 4.3 | 0.00 | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally. | ||
| CVE-2021-28070 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2021 | Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete. | ||
| CVE-2021-23431 | Med | 0.28 | 5.4 | 0.00 | Aug 24, 2021 | The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms. | ||
| CVE-2021-24380 | Med | 0.28 | 4.3 | 0.00 | Aug 16, 2021 | The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values. | ||
| CVE-2020-20989 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2021 | A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs. | ||
| CVE-2021-36543 | Med | 0.28 | 4.3 | 0.01 | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page. | ||
| CVE-2021-36542 | Med | 0.28 | 4.3 | 0.01 | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page. | ||
| CVE-2021-35343 | Med | 0.28 | 4.3 | 0.01 | Aug 3, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page. | ||
| CVE-2021-20786 | Med | 0.28 | 4.3 | 0.00 | Jul 30, 2021 | Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0)… | ||
| CVE-2021-20580 | Med | 0.28 | 4.3 | 0.00 | Jun 29, 2021 | IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241. | ||
| CVE-2021-34547 | Med | 0.28 | 4.3 | 0.00 | Jun 10, 2021 | PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation. | ||
| CVE-2020-35972 | Med | 0.28 | 4.3 | 0.01 | Jun 3, 2021 | An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html. | ||
| CVE-2020-24740 | Med | 0.28 | 4.3 | 0.00 | May 18, 2021 | An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage | ||
| CVE-2021-24251 | Med | 0.28 | 4.3 | 0.00 | May 6, 2021 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from… | ||
| CVE-2021-21644 | Med | 0.28 | 5.4 | 0.01 | Apr 21, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID. | ||
| CVE-2021-24172 | Med | 0.28 | 4.3 | 0.00 | Apr 5, 2021 | The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current . | ||
| CVE-2021-26216 | Med | 0.28 | 4.3 | 0.00 | Mar 18, 2021 | SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php. |
- risk 0.28cvss 4.3epss 0.00
The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned…
- risk 0.28cvss 4.3epss 0.00
The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set…
- risk 0.28cvss 4.3epss 0.00
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
- risk 0.28cvss 4.3epss 0.00
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.
- risk 0.28cvss 4.3epss 0.00
Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.
- risk 0.28cvss 5.4epss 0.00
The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.
- risk 0.28cvss 4.3epss 0.00
The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.
- risk 0.28cvss 4.3epss 0.00
A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs.
- risk 0.28cvss 4.3epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
- risk 0.28cvss 4.3epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.LockDocument.php in SeedDMS v5.1.x<5.1.23 and v6.0.x <6.0.16 allows a remote attacker to lock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
- risk 0.28cvss 4.3epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.Ajax.php in SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 allows a remote attacker to edit document name without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.
- risk 0.28cvss 4.3epss 0.00
Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0)…
- risk 0.28cvss 4.3epss 0.00
IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 198241.
- risk 0.28cvss 4.3epss 0.00
PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.
- risk 0.28cvss 4.3epss 0.00
An issue was discovered in Pluck 4.7.10-dev2. There is a CSRF vulnerability that can editpage via a /admin.php?action=editpage
- risk 0.28cvss 4.3epss 0.00
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from…
- risk 0.28cvss 5.4epss 0.01
A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.
- risk 0.28cvss 4.3epss 0.00
The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .
- risk 0.28cvss 4.3epss 0.00
SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.