VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,580)

page 6 of 479
  • CVE-2019-7262HigJul 2, 2019
    risk 0.62cvss 8.8epss 0.16

    Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).

  • CVE-2025-54782HigAug 2, 2025
    risk 0.61cvss 8.8epss 0.48

    Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP…

  • CVE-2024-42764CriAug 23, 2024
    risk 0.61cvss 9.4epss 0.00

    Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.

  • CVE-2022-26180HigApr 8, 2022
    risk 0.61cvss 8.8epss 0.04

    qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.

  • CVE-2021-24581HigAug 30, 2021
    risk 0.61cvss 8.8epss 0.04

    The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the…

  • CVE-2021-29995HigJun 9, 2021
    risk 0.61cvss 8.8epss 0.04

    A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.

  • CVE-2021-31762HigApr 25, 2021
    risk 0.61cvss 8.8epss 0.09

    Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.

  • CVE-2021-31152HigApr 14, 2021
    risk 0.61cvss 8.8epss 0.04

    Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.

  • CVE-2020-23342HigJan 19, 2021
    risk 0.61cvss 8.8epss 0.12

    A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

  • CVE-2020-13259HigSep 16, 2020
    risk 0.61cvss 8.8epss 0.05

    A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…

  • CVE-2020-25453HigSep 15, 2020
    risk 0.61cvss 8.8epss 0.06

    An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.

  • CVE-2019-7273HigJul 1, 2019
    risk 0.61cvss 8.8epss 0.04

    Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).

  • CVE-2019-11416HigApr 22, 2019
    risk 0.61cvss 8.8epss 0.04

    A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.

  • CVE-2019-11374HigApr 20, 2019
    risk 0.61cvss 8.8epss 0.10

    74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

  • CVE-2019-7391HigMar 21, 2019
    risk 0.61cvss 8.8epss 0.14

    ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.

  • CVE-2019-6967HigMar 21, 2019
    risk 0.61cvss 8.8epss 0.14

    AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.

  • CVE-2018-11538HigJun 1, 2018
    risk 0.61cvss 8.8epss 0.13

    servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.

  • CVE-2017-9414HigFeb 5, 2018
    risk 0.61cvss 8.8epss 0.15

    Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly have unspecified other…

  • CVE-2017-16886HigJan 12, 2018
    risk 0.61cvss 8.8epss 0.07

    The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.

  • CVE-2017-1000499HigJan 3, 2018
    risk 0.61cvss 8.8epss 0.08

    phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.