CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 65 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17217 | Hig | 0.57 | 8.8 | 0.00 | Oct 6, 2019 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service. | ||
| CVE-2019-15040 | Hig | 0.57 | 8.8 | 0.01 | Oct 2, 2019 | JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page. | ||
| CVE-2015-9445 | Hig | 0.57 | 8.8 | 0.01 | Sep 26, 2019 | The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation. | ||
| CVE-2019-16706 | Hig | 0.57 | 8.8 | 0.01 | Sep 23, 2019 | kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php. | ||
| CVE-2019-16660 | Hig | 0.57 | 8.8 | 0.01 | Sep 21, 2019 | joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF. | ||
| CVE-2019-16659 | Hig | 0.57 | 8.8 | 0.01 | Sep 21, 2019 | TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF. | ||
| CVE-2019-16658 | Hig | 0.57 | 8.8 | 0.01 | Sep 21, 2019 | TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF. | ||
| CVE-2015-9394 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2019 | The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. | ||
| CVE-2019-15089 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator. | ||
| CVE-2016-10989 | Hig | 0.57 | 8.8 | 0.01 | Sep 17, 2019 | The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF. | ||
| CVE-2016-10982 | Hig | 0.57 | 8.8 | 0.01 | Sep 17, 2019 | The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF. | ||
| CVE-2016-10978 | Hig | 0.57 | 8.8 | 0.01 | Sep 17, 2019 | The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF. | ||
| CVE-2016-10974 | Hig | 0.57 | 8.8 | 0.01 | Sep 17, 2019 | The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS. | ||
| CVE-2019-16311 | Hig | 0.57 | 8.8 | 0.01 | Sep 14, 2019 | NIUSHOP V1.11 has CSRF via search_info to index.php. | ||
| CVE-2016-10946 | Hig | 0.57 | 8.8 | 0.01 | Sep 13, 2019 | The wp-d3 plugin before 2.4.1 for WordPress has CSRF. | ||
| CVE-2016-10945 | Hig | 0.57 | 8.8 | 0.01 | Sep 13, 2019 | The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF. | ||
| CVE-2016-10944 | Hig | 0.57 | 8.8 | 0.01 | Sep 13, 2019 | The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF. | ||
| CVE-2019-5993 | Hig | 0.57 | 8.8 | 0.01 | Sep 12, 2019 | Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5992 | Hig | 0.57 | 8.8 | 0.01 | Sep 12, 2019 | Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2019-5986 | Hig | 0.57 | 8.8 | 0.01 | Sep 12, 2019 | Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI… |
- risk 0.57cvss 8.8epss 0.00
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service.
- risk 0.57cvss 8.8epss 0.01
JetBrains YouTrack versions before 2019.1 had a CSRF vulnerability on the settings page.
- risk 0.57cvss 8.8epss 0.01
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
- risk 0.57cvss 8.8epss 0.01
kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php.
- risk 0.57cvss 8.8epss 0.01
joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
- risk 0.57cvss 8.8epss 0.01
TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.
- risk 0.57cvss 8.8epss 0.01
TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.
- risk 0.57cvss 8.8epss 0.01
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator.
- risk 0.57cvss 8.8epss 0.01
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
- risk 0.57cvss 8.8epss 0.01
The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
- risk 0.57cvss 8.8epss 0.01
The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.
- risk 0.57cvss 8.8epss 0.01
NIUSHOP V1.11 has CSRF via search_info to index.php.
- risk 0.57cvss 8.8epss 0.01
The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
- risk 0.57cvss 8.8epss 0.01
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION PR-S300NE/RT-S300NE/RV-S340NE firmware version Ver. 19.41 and earlier, PR-S300HI/RT-S300HI/RV-S340HI…