CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 430 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59713 | Hig | 0.00 | 8.1 | 0.00 | Jul 6, 2026 | Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging… | ||
| CVE-2026-14800 | Med | 0.00 | 4.3 | 0.00 | Jul 6, 2026 | A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made… | ||
| CVE-2026-59520 | Med | 0.00 | 4.3 | 0.00 | Jul 5, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16. | ||
| CVE-2026-57766 | Hig | 0.00 | 8.8 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions. | ||
| CVE-2026-57761 | Hig | 0.00 | 7.1 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions. | ||
| CVE-2026-57759 | Hig | 0.00 | 8.8 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. | ||
| CVE-2026-57758 | Hig | 0.00 | 7.1 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions. | ||
| CVE-2026-57757 | Hig | 0.00 | 7.1 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions. | ||
| CVE-2026-57751 | Hig | 0.00 | 8.1 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions. | ||
| CVE-2026-57747 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions. | ||
| CVE-2026-57690 | Med | 0.00 | 4.3 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions. | ||
| CVE-2026-57723 | Hig | 0.00 | 7.4 | 0.00 | Jul 1, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12. | ||
| CVE-2026-12158 | Hig | 0.00 | 8.8 | 0.00 | Jul 1, 2026 | The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible… | ||
| CVE-2026-58518 | Med | 0.00 | 6.3 | 0.00 | Jul 1, 2026 | Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3. | ||
| CVE-2026-11981 | Med | 0.00 | 4.3 | 0.00 | Jul 1, 2026 | The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable… | ||
| CVE-2026-35096 | Med | 0.00 | — | 0.00 | Jun 30, 2026 | KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged POST request to the… | ||
| CVE-2026-8944 | Med | 0.00 | 4.3 | 0.00 | Jun 30, 2026 | The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible… | ||
| CVE-2026-31016 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint | ||
| CVE-2026-13537 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used. | ||
| CVE-2026-13422 | Med | 0.00 | 4.3 | 0.00 | Jun 27, 2026 | The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and… |
- risk 0.00cvss 8.1epss 0.00
Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging…
- risk 0.00cvss 4.3epss 0.00
A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made…
- risk 0.00cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.
- risk 0.00cvss 8.8epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
- risk 0.00cvss 8.8epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
- risk 0.00cvss 7.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.
- risk 0.00cvss 7.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.
- risk 0.00cvss 8.8epss 0.00
The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible…
- risk 0.00cvss 6.3epss 0.00
Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3.
- risk 0.00cvss 4.3epss 0.00
The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable…
- risk 0.00cvss —epss 0.00
KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged POST request to the…
- risk 0.00cvss 4.3epss 0.00
The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible…
- risk 0.00cvss 6.5epss 0.00
Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.
- risk 0.00cvss 4.3epss 0.00
The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and…