CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 66 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1261 | Hig | 0.57 | 8.8 | 0.02 | Sep 11, 2019 | A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a… | ||
| CVE-2019-1259 | Hig | 0.57 | 8.8 | 0.01 | Sep 11, 2019 | A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a… | ||
| CVE-2017-18607 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2019 | The avada theme before 5.1.5 for WordPress has CSRF. | ||
| CVE-2019-16099 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file. | ||
| CVE-2019-16059 | Hig | 0.57 | 8.8 | 0.01 | Sep 6, 2019 | Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML page. | ||
| CVE-2019-15868 | Hig | 0.57 | 8.8 | 0.01 | Sep 3, 2019 | The affiliates-manager plugin before 2.6.6 for WordPress has CSRF. | ||
| CVE-2019-15865 | Hig | 0.57 | 8.8 | 0.01 | Sep 3, 2019 | The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF. | ||
| CVE-2019-15841 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2019 | The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility. | ||
| CVE-2019-15840 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2019 | The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. | ||
| CVE-2019-15835 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2019 | The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. | ||
| CVE-2019-15834 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2019 | The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF. | ||
| CVE-2019-15832 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2019 | The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. | ||
| CVE-2019-15831 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2019 | The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. | ||
| CVE-2019-15828 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2019 | The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. | ||
| CVE-2015-9380 | Hig | 0.57 | 8.8 | 0.01 | Aug 30, 2019 | The photo-gallery plugin before 1.2.42 for WordPress has CSRF. | ||
| CVE-2019-15781 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2019 | The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF. | ||
| CVE-2019-15779 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2019 | The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete. | ||
| CVE-2019-15770 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2019 | The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. | ||
| CVE-2019-15769 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2019 | The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. | ||
| CVE-2019-15496 | Hig | 0.57 | 8.8 | 0.01 | Aug 28, 2019 | MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page. |
- risk 0.57cvss 8.8epss 0.02
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a…
- risk 0.57cvss 8.8epss 0.01
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a…
- risk 0.57cvss 8.8epss 0.01
The avada theme before 5.1.5 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
- risk 0.57cvss 8.8epss 0.01
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.
- risk 0.57cvss 8.8epss 0.01
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
- risk 0.57cvss 8.8epss 0.01
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete.
- risk 0.57cvss 8.8epss 0.01
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
- risk 0.57cvss 8.8epss 0.01
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
- risk 0.57cvss 8.8epss 0.01
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.