CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 68 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2011-5328 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The user-access-manager plugin before 1.2 for WordPress has CSRF. | ||
| CVE-2019-15229 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page. | ||
| CVE-2019-15115 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF. | ||
| CVE-2019-15114 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF. | ||
| CVE-2019-15113 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF. | ||
| CVE-2018-20974 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The js-jobs plugin before 1.0.7 for WordPress has CSRF. | ||
| CVE-2018-20972 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The companion-auto-update plugin before 3.2.1 for WordPress has CSRF. | ||
| CVE-2018-20971 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan. | ||
| CVE-2017-18547 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms. | ||
| CVE-2017-18546 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF. | ||
| CVE-2017-18544 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF. | ||
| CVE-2015-9322 | Hig | 0.57 | 8.8 | 0.01 | Aug 16, 2019 | The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF. | ||
| CVE-2019-13516 | Hig | 0.57 | 8.8 | 0.01 | Aug 15, 2019 | In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect. | ||
| CVE-2019-14216 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP archive containing a .php file. | ||
| CVE-2019-10199 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain. | ||
| CVE-2018-20968 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF. | ||
| CVE-2018-20967 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. | ||
| CVE-2017-18513 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface. | ||
| CVE-2017-18512 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF. | ||
| CVE-2017-18511 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF. |
- risk 0.57cvss 8.8epss 0.01
The user-access-manager plugin before 1.2 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The js-jobs plugin before 1.0.7 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
- risk 0.57cvss 8.8epss 0.01
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
- risk 0.57cvss 8.8epss 0.01
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
- risk 0.57cvss 8.8epss 0.01
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection setting that has not taken effect.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/admin.php?page=wp-svg-icons-custom-set mishandles Custom Icon uploads. CSRF leads to upload of a ZIP archive containing a .php file.
- risk 0.57cvss 8.8epss 0.01
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
- risk 0.57cvss 8.8epss 0.01
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
- risk 0.57cvss 8.8epss 0.01
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.