CWE-352
Cross-Site Request Forgery (CSRF)
Description
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62
CVEs mapped to this weakness (9,624)
page 69 of 482| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18510 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions. | ||
| CVE-2016-10885 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-editor plugin before 1.2.6 for WordPress has CSRF. | ||
| CVE-2016-10884 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues. | ||
| CVE-2016-10882 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The google-document-embedder plugin before 2.6.2 for WordPress has CSRF. | ||
| CVE-2015-9309 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. | ||
| CVE-2015-9308 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. | ||
| CVE-2015-9307 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. | ||
| CVE-2013-7476 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface. | ||
| CVE-2019-11207 | Hig | 0.57 | 8.8 | 0.01 | Aug 13, 2019 | The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and reflected cross-site scripting (XSS) attacks, as well as… | ||
| CVE-2018-20964 | Hig | 0.57 | 8.8 | 0.01 | Aug 13, 2019 | The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. | ||
| CVE-2017-18504 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2019 | The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF. | ||
| CVE-2016-10876 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2019 | The wp-database-backup plugin before 4.3.1 for WordPress has CSRF. | ||
| CVE-2016-10874 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2019 | The wp-database-backup plugin before 4.3.3 for WordPress has CSRF. | ||
| CVE-2016-10863 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2019 | Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure. | ||
| CVE-2016-10862 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2019 | Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page. | ||
| CVE-2015-9292 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2019 | 6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter). | ||
| CVE-2019-14681 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2019 | The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF. | ||
| CVE-2019-1958 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2019 | A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI… | ||
| CVE-2019-10386 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through… | ||
| CVE-2019-10368 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using… |
- risk 0.57cvss 8.8epss 0.01
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.
- risk 0.57cvss 8.8epss 0.01
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
- risk 0.57cvss 8.8epss 0.01
The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
- risk 0.57cvss 8.8epss 0.01
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
- risk 0.57cvss 8.8epss 0.01
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
- risk 0.57cvss 8.8epss 0.01
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
- risk 0.57cvss 8.8epss 0.01
The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and reflected cross-site scripting (XSS) attacks, as well as…
- risk 0.57cvss 8.8epss 0.01
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.01
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
- risk 0.57cvss 8.8epss 0.01
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
- risk 0.57cvss 8.8epss 0.01
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
- risk 0.57cvss 8.8epss 0.01
The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.
- risk 0.57cvss 8.8epss 0.01
A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI…
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through…
- risk 0.57cvss 8.8epss 0.01
A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using…