VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,725)

page 6 of 487
  • CVE-2015-20105CriDec 2, 2021
    risk 0.62cvss 9.6epss 0.01

    The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored…

  • CVE-2021-38480CriOct 19, 2021
    risk 0.62cvss 9.6epss 0.01

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management…

  • CVE-2020-36283CriMar 24, 2021
    risk 0.62cvss 9.6epss 0.01

    HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the…

  • CVE-2013-3568HigFeb 6, 2020
    risk 0.62cvss 8.8epss 0.25

    Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

  • CVE-2019-12624HigAug 21, 2019
    risk 0.62cvss 8.8epss 0.18

    A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The…

  • CVE-2019-7262HigJul 2, 2019
    risk 0.62cvss 8.8epss 0.16

    Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).

  • CVE-2025-54782HigAug 2, 2025
    risk 0.61cvss 8.8epss 0.51

    Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP…

  • CVE-2024-42764CriAug 23, 2024
    risk 0.61cvss 9.4epss 0.00

    Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.

  • CVE-2022-26180HigApr 8, 2022
    risk 0.61cvss 8.8epss 0.04

    qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.

  • CVE-2021-24581HigAug 30, 2021
    risk 0.61cvss 8.8epss 0.04

    The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the…

  • CVE-2021-29995HigJun 9, 2021
    risk 0.61cvss 8.8epss 0.04

    A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

  • CVE-2021-31762HigApr 25, 2021
    risk 0.61cvss 8.8epss 0.09

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.

  • CVE-2021-31152HigApr 14, 2021
    risk 0.61cvss 8.8epss 0.04

    Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.

  • CVE-2020-23342HigJan 19, 2021
    risk 0.61cvss 8.8epss 0.12

    A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

  • CVE-2020-13259HigSep 16, 2020
    risk 0.61cvss 8.8epss 0.05

    A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2020-25453HigSep 15, 2020
    risk 0.61cvss 8.8epss 0.06

    An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.

  • CVE-2019-7273HigJul 1, 2019
    risk 0.61cvss 8.8epss 0.04

    Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).

  • CVE-2019-11416HigApr 22, 2019
    risk 0.61cvss 8.8epss 0.04

    A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.

  • CVE-2019-11374HigApr 20, 2019
    risk 0.61cvss 8.8epss 0.10

    74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

  • CVE-2019-10874HigApr 5, 2019
    risk 0.61cvss 8.8epss 0.05

    Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.