VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 431 of 479
  • CVE-2026-52784HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST parameter "user[admin]". This vulnerability is fixed in 17.3.3 and 17.4.1.

  • CVE-2026-57659HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.

  • CVE-2026-57657MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.

  • CVE-2026-57655HigJun 26, 2026
    risk 0.00cvss 8.2epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.

  • CVE-2026-57641MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

  • CVE-2026-57637MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

  • CVE-2026-57635MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.

  • CVE-2025-68052HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

  • CVE-2026-54220HigJun 18, 2026
    risk 0.00cvss epss 0.00

    uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions. Because vendor contact attempts were unsuccessful, the vulnerability has only been…

  • CVE-2015-20117MedMar 16, 2026
    risk 0.00cvss 5.3epss 0.00

    Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to…

  • CVE-2015-20113MedMar 16, 2026
    risk 0.00cvss 5.3epss 0.00

    Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malicious scripts. Attackers can craft malicious web pages that execute unauthorized…

  • CVE-2026-31954NonMar 11, 2026
    risk 0.00cvss 0.0epss 0.00

    Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.

  • CVE-2026-24885MedFeb 10, 2026
    risk 0.00cvss 5.7epss 0.00

    Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard application. The application fails to strictly enforce the application/json…

  • CVE-2026-25221HigFeb 2, 2026
    risk 0.00cvss 8.1epss 0.00

    PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, the OAuth 2.0 implementation for GitHub and Google login providers is vulnerable to Login Cross-Site Request Forgery (CSRF). The application fails to implement and verify the state parameter…

  • CVE-2026-24408NonJan 26, 2026
    risk 0.00cvss 0.0epss 0.00

    sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. `_OAuthSession` creates a unique "state" and sends it as a parameter in the…

  • CVE-2026-22800LowJan 12, 2026
    risk 0.00cvss 2.4epss 0.00

    PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Request Forgery (CSRF) vulnerability exists in an administrative API endpoint responsible for terminating all active video conferences on a single server. The…

  • CVE-2025-59949MedDec 18, 2025
    risk 0.00cvss 5.3epss 0.00

    FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via . Version 1.27.1 patches the issue.

  • CVE-2025-68434HigDec 17, 2025
    risk 0.00cvss 8.8epss 0.00

    Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter…

  • CVE-2025-65203HigDec 17, 2025
    risk 0.00cvss 7.1epss 0.00

    KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and…

  • CVE-2025-66629LowDec 5, 2025
    risk 0.00cvss 3.7epss 0.00

    HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social login providers such as Google, GitHub, GitLab, Facebook or Dropbox lack CSRF protection, since they don't send a state parameter and…