CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,580)
page 6 of 479| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-7262 | Hig | 0.62 | 8.8 | 0.16 | Jul 2, 2019 | Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). | ||
| CVE-2025-54782 | Hig | 0.61 | 8.8 | 0.48 | Aug 2, 2025 | Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP… | ||
| CVE-2024-42764 | Cri | 0.61 | 9.4 | 0.00 | Aug 23, 2024 | Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php. | ||
| CVE-2022-26180 | Hig | 0.61 | 8.8 | 0.04 | Apr 8, 2022 | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. | ||
| CVE-2021-24581 | Hig | 0.61 | 8.8 | 0.04 | Aug 30, 2021 | The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the… | ||
| CVE-2021-29995 | Hig | 0.61 | 8.8 | 0.04 | Jun 9, 2021 | A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1. | ||
| CVE-2021-31762 | Hig | 0.61 | 8.8 | 0.09 | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature. | ||
| CVE-2021-31152 | Hig | 0.61 | 8.8 | 0.04 | Apr 14, 2021 | Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers. | ||
| CVE-2020-23342 | Hig | 0.61 | 8.8 | 0.12 | Jan 19, 2021 | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. | ||
| CVE-2020-13259 | Hig | 0.61 | 8.8 | 0.05 | Sep 16, 2020 | A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF… | ||
| CVE-2020-25453 | Hig | 0.61 | 8.8 | 0.06 | Sep 15, 2020 | An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. | ||
| CVE-2019-7273 | Hig | 0.61 | 8.8 | 0.04 | Jul 1, 2019 | Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). | ||
| CVE-2019-11416 | Hig | 0.61 | 8.8 | 0.04 | Apr 22, 2019 | A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user. | ||
| CVE-2019-11374 | Hig | 0.61 | 8.8 | 0.10 | Apr 20, 2019 | 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. | ||
| CVE-2019-7391 | Hig | 0.61 | 8.8 | 0.14 | Mar 21, 2019 | ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF. | ||
| CVE-2019-6967 | Hig | 0.61 | 8.8 | 0.14 | Mar 21, 2019 | AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF. | ||
| CVE-2018-11538 | Hig | 0.61 | 8.8 | 0.13 | Jun 1, 2018 | servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass. | ||
| CVE-2017-9414 | Hig | 0.61 | 8.8 | 0.15 | Feb 5, 2018 | Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly have unspecified other… | ||
| CVE-2017-16886 | Hig | 0.61 | 8.8 | 0.07 | Jan 12, 2018 | The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal. | ||
| CVE-2017-1000499 | Hig | 0.61 | 8.8 | 0.08 | Jan 3, 2018 | phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc. |
- risk 0.62cvss 8.8epss 0.16
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
- risk 0.61cvss 8.8epss 0.48
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP…
- risk 0.61cvss 9.4epss 0.00
Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.
- risk 0.61cvss 8.8epss 0.04
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
- risk 0.61cvss 8.8epss 0.04
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the…
- risk 0.61cvss 8.8epss 0.04
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.
- risk 0.61cvss 8.8epss 0.09
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.
- risk 0.61cvss 8.8epss 0.04
Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.
- risk 0.61cvss 8.8epss 0.12
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
- risk 0.61cvss 8.8epss 0.05
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…
- risk 0.61cvss 8.8epss 0.06
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
- risk 0.61cvss 8.8epss 0.04
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
- risk 0.61cvss 8.8epss 0.04
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.
- risk 0.61cvss 8.8epss 0.10
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
- risk 0.61cvss 8.8epss 0.14
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
- risk 0.61cvss 8.8epss 0.14
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
- risk 0.61cvss 8.8epss 0.13
servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.
- risk 0.61cvss 8.8epss 0.15
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly have unspecified other…
- risk 0.61cvss 8.8epss 0.07
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.
- risk 0.61cvss 8.8epss 0.08
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.