CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,725)
page 6 of 487| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-20105 | Cri | 0.62 | 9.6 | 0.01 | Dec 2, 2021 | The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored… | ||
| CVE-2021-38480 | Cri | 0.62 | 9.6 | 0.01 | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management… | ||
| CVE-2020-36283 | Cri | 0.62 | 9.6 | 0.01 | Mar 24, 2021 | HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the… | ||
| CVE-2013-3568 | Hig | 0.62 | 8.8 | 0.25 | Feb 6, 2020 | Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. | ||
| CVE-2019-12624 | Hig | 0.62 | 8.8 | 0.18 | Aug 21, 2019 | A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The… | ||
| CVE-2019-7262 | Hig | 0.62 | 8.8 | 0.16 | Jul 2, 2019 | Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). | ||
| CVE-2025-54782 | Hig | 0.61 | 8.8 | 0.51 | Aug 2, 2025 | Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP… | ||
| CVE-2024-42764 | Cri | 0.61 | 9.4 | 0.00 | Aug 23, 2024 | Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php. | ||
| CVE-2022-26180 | Hig | 0.61 | 8.8 | 0.04 | Apr 8, 2022 | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. | ||
| CVE-2021-24581 | Hig | 0.61 | 8.8 | 0.04 | Aug 30, 2021 | The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the… | ||
| CVE-2021-29995 | Hig | 0.61 | 8.8 | 0.04 | Jun 9, 2021 | A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1. | ||
| CVE-2021-31762 | Hig | 0.61 | 8.8 | 0.09 | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature. | ||
| CVE-2021-31152 | Hig | 0.61 | 8.8 | 0.04 | Apr 14, 2021 | Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers. | ||
| CVE-2020-23342 | Hig | 0.61 | 8.8 | 0.12 | Jan 19, 2021 | A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users. | ||
| CVE-2020-13259 | Hig | 0.61 | 8.8 | 0.05 | Sep 16, 2020 | A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF… | ||
| CVE-2020-25453 | Hig | 0.61 | 8.8 | 0.06 | Sep 15, 2020 | An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. | ||
| CVE-2019-7273 | Hig | 0.61 | 8.8 | 0.04 | Jul 1, 2019 | Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). | ||
| CVE-2019-11416 | Hig | 0.61 | 8.8 | 0.04 | Apr 22, 2019 | A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user. | ||
| CVE-2019-11374 | Hig | 0.61 | 8.8 | 0.10 | Apr 20, 2019 | 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. | ||
| CVE-2019-10874 | Hig | 0.61 | 8.8 | 0.05 | Apr 5, 2019 | Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file. |
- risk 0.62cvss 9.6epss 0.01
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored…
- risk 0.62cvss 9.6epss 0.01
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management…
- risk 0.62cvss 9.6epss 0.01
HID OMNIKEY 5427 and OMNIKEY 5127 readers are vulnerable to CSRF when using the EEM driver (Ethernet Emulation Mode). By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to upload a configuration file to the…
- risk 0.62cvss 8.8epss 0.25
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
- risk 0.62cvss 8.8epss 0.18
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The…
- risk 0.62cvss 8.8epss 0.16
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
- risk 0.61cvss 8.8epss 0.51
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP…
- risk 0.61cvss 9.4epss 0.00
Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.
- risk 0.61cvss 8.8epss 0.04
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
- risk 0.61cvss 8.8epss 0.04
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the…
- risk 0.61cvss 8.8epss 0.04
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in user (including script execution). The issue is resolved in CloverDX 5.10, CloverDX 5.9.1, CloverDX 5.8.2, and CloverDX 5.7.1.
- risk 0.61cvss 8.8epss 0.09
Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.
- risk 0.61cvss 8.8epss 0.04
Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.
- risk 0.61cvss 8.8epss 0.12
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
- risk 0.61cvss 8.8epss 0.05
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF…
- risk 0.61cvss 8.8epss 0.06
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
- risk 0.61cvss 8.8epss 0.04
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
- risk 0.61cvss 8.8epss 0.04
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.
- risk 0.61cvss 8.8epss 0.10
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
- risk 0.61cvss 8.8epss 0.05
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.