VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 432 of 479
  • CVE-2025-64133MedOct 29, 2025
    risk 0.00cvss 5.4epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to execute sandboxed Groovy code.

  • CVE-2025-61604HigOct 2, 2025
    risk 0.00cvss 7.1epss 0.00

    WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-Site Request Forgery (CSRF) vulnerability. The delete operation for the Almoxarifado entity is exposed via HTTP GET without CSRF protection, allowing a…

  • CVE-2025-53095CriJul 1, 2025
    risk 0.00cvss 9.6epss 0.00

    Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious web page that, when visited by an…

  • CVE-2025-5410MedJun 1, 2025
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability affects the function session_start_response of the file src/mist/api/auth/middleware.py. The manipulation leads to cross-site request forgery. The attack can…

  • CVE-2025-31690HigMar 31, 2025
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1.

  • CVE-2025-31689HigMar 31, 2025
    risk 0.00cvss 8.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2.

  • CVE-2024-9847HigMar 20, 2025
    risk 0.00cvss 8.0epss 0.00

    FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a victim user. The attacker can craft a malicious link or script that, when clicked by an authenticated user, will send a…

  • CVE-2025-24897HigFeb 11, 2025
    risk 0.00cvss 8.2epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection and the lack of proper security attributes in the authentication cookies of Bull's dashboard, some of the APIs of…

  • CVE-2025-24398HigJan 22, 2025
    risk 0.00cvss 8.8epss 0.00

    Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

  • CVE-2025-23044MedJan 20, 2025
    risk 0.00cvss 6.8epss 0.00

    PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behalf. This includes GET and POST requests due to the missing SameSite= attribute on cookies and the ability to refresh cookies.…

  • CVE-2024-55089MedDec 18, 2024
    risk 0.00cvss 4.1epss 0.00

    Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may contain external entities.

  • CVE-2024-30617MedNov 4, 2024
    risk 0.00cvss 5.4epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.

  • CVE-2024-6673MedOct 29, 2024
    risk 0.00cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker…

  • CVE-2024-5616MedJul 6, 2024
    risk 0.00cvss 4.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which allows attackers to trick victims into deleting installed models. By crafting a malicious HTML page, an attacker can cause the deletion of a model, such as…

  • CVE-2024-37306HigJun 13, 2024
    risk 0.00cvss 7.1epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, if an attacker can trick a logged-in CVAT user into visiting a malicious URL, they can initiate a dataset export…

  • CVE-2024-2288HigJun 6, 2024
    risk 0.00cvss 8.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, specifically in the parisneo/lollms-webui repository, affecting versions up to 7.3.0. This vulnerability allows attackers to change a victim's profile…

  • CVE-2024-1879HigJun 6, 2024
    risk 0.00cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability in significant-gravitas/autogpt version v0.5.0 allows attackers to execute arbitrary commands on the AutoGPT server. The vulnerability stems from the lack of protections on the API endpoint receiving instructions, enabling an…

  • CVE-2024-34007HigMay 31, 2024
    risk 0.00cvss 8.8epss 0.00

    The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

  • CVE-2024-31205MedApr 8, 2024
    risk 0.00cvss 4.2epss 0.00

    Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set request forgery (CSRF) validation when calling refresh token mutation with empty string. When a user…

  • CVE-2024-30965HigApr 2, 2024
    risk 0.00cvss 8.8epss 0.00

    DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.