VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 394 of 479
  • CVE-2023-39061LowAug 21, 2023
    risk 0.23cvss 3.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.

  • CVE-2023-23847LowFeb 15, 2023
    risk 0.23cvss 3.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…

  • CVE-2022-45228LowDec 12, 2022
    risk 0.23cvss 3.5epss 0.00

    Dragino Lora LG01 18ed40 IoT v4.3.4 was discovered to contain a Cross-Site Request Forgery in the logout page.

  • CVE-2022-45393LowNov 15, 2022
    risk 0.23cvss 3.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.

  • CVE-2022-23111MedJan 12, 2022
    risk 0.23cvss 4.3epss 0.27

    A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2020-18464LowAug 12, 2021
    risk 0.23cvss 3.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in AikCms 2.0.0 in video_list.php, which can let a malicious user delete movie information.

  • CVE-2021-26071LowApr 1, 2021
    risk 0.23cvss 3.5epss 0.00

    The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site…

  • CVE-2020-28838LowDec 11, 2020
    risk 0.23cvss 3.5epss 0.00

    Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.

  • CVE-2018-7677LowMar 14, 2018
    risk 0.23cvss 3.5epss 0.01

    A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.

  • CVE-2017-5244LowJun 15, 2017
    risk 0.23cvss 3.5epss 0.01

    Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of the service. This could have allowed an attacker to stop currently-running…

  • CVE-2016-3009LowNov 30, 2016
    risk 0.23cvss 3.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.

  • CVE-2016-2998LowSep 1, 2016
    risk 0.23cvss 3.5epss 0.00

    Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update data.

  • CVE-2026-34384MedMar 31, 2026
    risk 0.22cvss 4.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. Unlike the delete_user mode in…

  • CVE-2025-23113LowJan 10, 2025
    risk 0.22cvss 3.4epss 0.00

    An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containing a list of alert configuration. An attacker can send the victim a CSV file containing an HTML injection payload in the…

  • CVE-2024-39326MedJul 2, 2024
    risk 0.22cvss 4.4epss 0.00

    SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectname}/skills/{skillname}/video` (and probably others) is open to a cross-site request forgery (CSRF) vulnerability. Due to the endpoint being CSRFable e.g POST…

  • CVE-2024-3471LowMay 2, 2024
    risk 0.22cvss 3.4epss 0.00

    The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

  • CVE-2023-47635MedFeb 20, 2024
    risk 0.22cvss 4.5epss 0.00

    Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for the questionnaire templates preview. The issue does not imply a serious security thread as you need to have…

  • CVE-2020-14506LowSep 18, 2020
    risk 0.22cvss 3.4epss 0.00

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

  • CVE-2025-10308MedAug 14, 2026
    risk 0.21cvss 4.3epss 0.00

    The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete…

  • CVE-2026-19786MedAug 14, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. Upgrading to version 12.9 is…