VYPR

CWE-352

Cross-Site Request Forgery (CSRF)

CompoundStableLikelihood: Medium

Description

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-462 · CAPEC-467 · CAPEC-62

CVEs mapped to this weakness (9,624)

page 69 of 482
  • CVE-2017-18510HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.

  • CVE-2016-10885HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-editor plugin before 1.2.6 for WordPress has CSRF.

  • CVE-2016-10884HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.

  • CVE-2016-10882HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.

  • CVE-2015-9309HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.

  • CVE-2015-9308HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

  • CVE-2015-9307HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.

  • CVE-2013-7476HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.

  • CVE-2019-11207HigAug 13, 2019
    risk 0.57cvss 8.8epss 0.01

    The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and reflected cross-site scripting (XSS) attacks, as well as…

  • CVE-2018-20964HigAug 13, 2019
    risk 0.57cvss 8.8epss 0.01

    The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.

  • CVE-2017-18504HigAug 12, 2019
    risk 0.57cvss 8.8epss 0.01

    The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.

  • CVE-2016-10876HigAug 12, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.

  • CVE-2016-10874HigAug 12, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.

  • CVE-2016-10863HigAug 8, 2019
    risk 0.57cvss 8.8epss 0.01

    Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.

  • CVE-2016-10862HigAug 8, 2019
    risk 0.57cvss 8.8epss 0.01

    Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.

  • CVE-2015-9292HigAug 8, 2019
    risk 0.57cvss 8.8epss 0.01

    6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).

  • CVE-2019-14681HigAug 8, 2019
    risk 0.57cvss 8.8epss 0.01

    The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove=true CSRF.

  • CVE-2019-1958HigAug 8, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI…

  • CVE-2019-10386HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through…

  • CVE-2019-10368HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using…