CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 67 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-11457 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/. | ||
| CVE-2019-15660 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | The wp-members plugin before 3.2.8 for WordPress has CSRF. | ||
| CVE-2019-15645 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. | ||
| CVE-2018-21006 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF. | ||
| CVE-2018-21002 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. | ||
| CVE-2015-9343 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | The wp-rollback plugin before 1.2.3 for WordPress has CSRF. | ||
| CVE-2019-15491 | Hig | 0.57 | 8.8 | 0.01 | Aug 23, 2019 | openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. | ||
| CVE-2019-15329 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2019 | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. | ||
| CVE-2016-10918 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2019 | The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF. | ||
| CVE-2019-13477 | Hig | 0.57 | 8.8 | 0.01 | Aug 21, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account. | ||
| CVE-2017-18521 | Hig | 0.57 | 8.8 | 0.01 | Aug 21, 2019 | The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n. | ||
| CVE-2016-10903 | Hig | 0.57 | 8.8 | 0.01 | Aug 21, 2019 | The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF. | ||
| CVE-2016-10902 | Hig | 0.57 | 8.8 | 0.01 | Aug 21, 2019 | The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools. | ||
| CVE-2019-4117 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158116. | ||
| CVE-2017-18523 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book. | ||
| CVE-2019-15238 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. | ||
| CVE-2017-18569 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The my-wp-translate plugin before 1.0.4 for WordPress has CSRF. | ||
| CVE-2016-10915 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF. | ||
| CVE-2016-10914 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file. | ||
| CVE-2014-10381 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The user-domain-whitelist plugin before 1.5 for WordPress has CSRF. |
- risk 0.57cvss 8.8epss 0.01
Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-admin/, /comment/add/, /documents/1/view/, /documents/create/, /opportunities/create/, and /login/.
- risk 0.57cvss 8.8epss 0.01
The wp-members plugin before 3.2.8 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
- risk 0.57cvss 8.8epss 0.01
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to change the password for the root account.
- risk 0.57cvss 8.8epss 0.01
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.
- risk 0.57cvss 8.8epss 0.01
The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
- risk 0.57cvss 8.8epss 0.01
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158116.
- risk 0.57cvss 8.8epss 0.01
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
- risk 0.57cvss 8.8epss 0.01
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
- risk 0.57cvss 8.8epss 0.01
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
- risk 0.57cvss 8.8epss 0.01
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.