VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 430 of 479
  • CVE-2026-59713HigJul 6, 2026
    risk 0.00cvss 8.1epss 0.00

    Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation, logging…

  • CVE-2026-14800MedJul 6, 2026
    risk 0.00cvss 4.3epss 0.00

    A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made…

  • CVE-2026-59520MedJul 5, 2026
    risk 0.00cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.

  • CVE-2026-57766HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

  • CVE-2026-57761HigJul 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

  • CVE-2026-57759HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

  • CVE-2026-57758HigJul 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

  • CVE-2026-57757HigJul 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.

  • CVE-2026-57751HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

  • CVE-2026-57747MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

  • CVE-2026-57690MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.

  • CVE-2026-57723HigJul 1, 2026
    risk 0.00cvss 7.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.

  • CVE-2026-12158HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible…

  • CVE-2026-58518MedJul 1, 2026
    risk 0.00cvss 6.3epss 0.00

    Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3.

  • CVE-2026-11981MedJul 1, 2026
    risk 0.00cvss 4.3epss 0.00

    The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable…

  • CVE-2026-35096MedJun 30, 2026
    risk 0.00cvss epss 0.00

    KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged POST request to the…

  • CVE-2026-8944MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the Google Analytics settings page (ga.php). This makes it possible…

  • CVE-2026-31016MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint

  • CVE-2026-13537MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.

  • CVE-2026-13422MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to missing or incorrect nonce validation on the hdq_validate_nonce function. This makes it possible for unauthenticated attackers to delete or modify quizzes and…