VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 391 of 479
  • CVE-2021-36915MedOct 11, 2022
    risk 0.27cvss 4.2epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows uploading the JSON file and updating the options. Requires Import and Export add-on.

  • CVE-2022-34347MedAug 22, 2022
    risk 0.27cvss 4.2epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.

  • CVE-2022-25778MedMay 4, 2022
    risk 0.27cvss 4.2epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user session.

  • CVE-2021-43846MedDec 20, 2021
    risk 0.27cvss 5.3epss 0.01

    `solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior to 3.1.5, 3.0.5, and 2.11.14 contain a cross-site request forgery (CSRF) vulnerability that allows a malicious site to add an item to the user's cart without…

  • CVE-2021-39198MedNov 19, 2021
    risk 0.27cvss 4.2epss 0.00

    OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this…

  • CVE-2019-10176MedAug 2, 2019
    risk 0.27cvss 4.2epss 0.01

    A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use…

  • CVE-2019-1003017MedFeb 6, 2019
    risk 0.27cvss 5.3epss 0.01

    A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from a preconfigured other Jenkins instance, potentially installing additional plugins necessary to load the imported job's…

  • CVE-2026-73423MedAug 12, 2026
    risk 0.26cvss epss 0.00

    Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware() primitive, while actions() and pages() can dispatch to user code independently. Mounting actions() before…

  • CVE-2023-37465medJul 27, 2026
    risk 0.26cvss epss

    ### Impact It's possible to forge a request to delete a message. ### Patches The problem has been patched in version 2.0-rc-1 of Discussion Extension. ### Workarounds There's no easy workaround except upgrading. ### References https://jira.xwiki.org/browse/DISCUSSION-22 ###…

  • CVE-2026-52823medJul 14, 2026
    risk 0.26cvss epss

    ### Summary Kimai 2.56.0 contains authenticated cross-site request forgery issues in its timesheet state-changing API endpoints. The application reuses the browser's existing session for `/api/*` requests, and both the `stop` and `restart` operations are exposed through `GET`…

  • CVE-2026-49992medJul 13, 2026
    risk 0.26cvss epss

    ### Summary Kimai 2.56.0 contains authenticated cross-site request forgery issues in its default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly create or reuse a `Team`, add the current user as…

  • CVE-2026-53760medJul 9, 2026
    risk 0.26cvss epss

    ## Summary The `modules/plugins.php` endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because these are top-level navigations, browsers include `SameSite=Lax` session cookies. An attacker crafts a…

  • CVE-2026-49455medJul 8, 2026
    risk 0.26cvss epss

    ## Summary Waku's RSC request dispatcher invokes server actions without validating the request's `Origin` (or `Sec-Fetch-Site`) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated `POST` to a registered server action endpoint using…

  • CVE-2019-25313MedFeb 11, 2026
    risk 0.26cvss 4.0epss 0.00

    FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new…

  • CVE-2025-66407MedDec 16, 2025
    risk 0.26cvss 5.0epss 0.00

    Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, prior to version 5.15, the…

  • CVE-2024-43787MedAug 22, 2024
    risk 0.26cvss 5.0epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass…

  • CVE-2024-5030LowNov 18, 2024
    risk 0.25cvss 3.8epss 0.00

    The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack

  • CVE-2024-39157LowJun 27, 2024
    risk 0.25cvss 3.8epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1.

  • CVE-2024-39156LowJun 27, 2024
    risk 0.25cvss 3.8epss 0.00

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.

  • CVE-2024-35039LowMay 16, 2024
    risk 0.25cvss 3.8epss 0.00

    idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.