CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,376 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 16 of 188
- CVE-2013-7473HIGHCVSS 8.8EG 8.82019-08-01
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
- CVE-2013-7476HIGHCVSS 8.8EG 8.82019-08-14
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
- CVE-2014-0010MEDIUMCVSS v2 6.8EG 6.82014-01-20
Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authent…
- CVE-2014-0026MEDIUMCVSS 6.5EG 6.52019-12-11
katello-headpin is vulnerable to CSRF in REST API
- CVE-2014-0120HIGHCVSS 8.8EG 8.82017-12-29
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdo…
- CVE-2014-0151MEDIUMCVSS v2 6.8EG 6.82015-02-13
Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.
- CVE-2014-0197HIGHCVSS 8.8EG 8.82019-12-13
CFME: CSRF protection vulnerability via permissive check of the referrer header
- CVE-2014-0336MEDIUMCVSS v2 6.8EG 6.82014-03-06
Cross-site request forgery (CSRF) vulnerability in the web client in Serena Dimensions CM 12.2 build 7.199.0 allows remote attackers to hijack the authentication of administrators for requests that use the user_new_master parameter to the …
- CVE-2014-0570MEDIUMCVSS v2 6.8EG 6.82014-10-15
Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to hijack the authentication of un…
- CVE-2014-0594HIGHCVSS 8.8EG 8.82018-06-08
In the Open Build Service (OBS) before version 2.4.6 the CSRF protection is incorrectly disabled in the web interface, allowing for requests without the user's consent.
- CVE-2014-0621MEDIUMCVSS v2 6.8EG 6.82014-01-08
Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to hijack the authentication of administrators for requests that (1) perform a factory reset via a reques…
- CVE-2014-0641MEDIUMCVSS v2 6.8EG 6.82014-08-20
Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to hijack the authentication of arbitrary users.
- CVE-2014-0736MEDIUMCVSS v2 6.8EG 6.82014-02-20
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of a…
- CVE-2014-0740MEDIUMCVSS v2 6.8EG 6.82014-02-27
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote att…
- CVE-2014-0745MEDIUMCVSS v2 6.8EG 6.82014-02-27
Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCum95502.
- CVE-2014-0813MEDIUMCVSS v2 6.8EG 6.82014-02-14
Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentication of arbitrary users for requests that modify settings.
- CVE-2014-0831MEDIUMCVSS v2 6.8EG 6.82014-02-01
Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configurati…
- CVE-2014-0835MEDIUMCVSS v2 6.8EG 6.82014-01-30
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify console Auto Update settings.
- CVE-2014-0864MEDIUMCVSS v2 6.8EG 6.82014-07-07
Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitra…
- CVE-2014-0873MEDIUMCVSS v2 6.8EG 6.82014-03-16
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 …
- CVE-2014-0885MEDIUMCVSS v2 6.8EG 6.82014-03-25
Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2014-0929MEDIUMCVSS v2 6.0EG 6.02014-06-08
Cross-site request forgery (CSRF) vulnerability in the Profiles component in IBM Connections through 3.0.1.1 CR3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that trigger follow actions.
- CVE-2014-0933MEDIUMCVSS v2 6.8EG 6.82014-05-16
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hijack the authentication of arbitrary users.
- CVE-2014-0944MEDIUMCVSS v2 6.0EG 6.02014-05-09
Cross-site request forgery (CSRF) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to hijack th…
- CVE-2014-0961MEDIUMCVSS v2 6.0EG 6.02014-06-08
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the a…
- CVE-2014-0969MEDIUMCVSS v2 6.8EG 6.82014-08-17
Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Manage…
- CVE-2014-100001MEDIUMCVSS v2 6.8EG 6.82015-01-13
Cross-site request forgery (CSRF) vulnerability in the SEO Plugin LiveOptim plugin before 1.1.4-free for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecif…
- CVE-2014-100005CRITICALCVSS 8.0EG 9.0⚠ KEV2015-01-13
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator …
- CVE-2014-10001MEDIUMCVSS v2 6.8EG 6.82015-01-13
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via t…
- CVE-2014-100025MEDIUMCVSS v2 6.8EG 6.82015-01-13
Cross-site request forgery (CSRF) vulnerability in index.php/user_data/insert_user in Savsoft Quiz allows remote attackers to hijack the authentication of administrators for requests that create an administrator account via a crafted reque…
- CVE-2014-10006MEDIUMCVSS v2 6.8EG 6.82015-01-13
Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attackers to hijack the authentication of unspecified users for requests that conduct cross-site scripting (XSS) attacks via the width parameter …
- CVE-2014-10008MEDIUMCVSS v2 6.8EG 6.82015-01-13
Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authentication of administrators for requests that add (1) an administrator via a crafted request to the admin page, (2) an ag…
- CVE-2014-10014MEDIUMCVSS v2 6.8EG 6.82015-01-13
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the adminis…
- CVE-2014-10019MEDIUMCVSS v2 6.8EG 6.82015-01-13
Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allow remote attackers to hijack the authentication of administrators for requests that (1) change t…
- CVE-2014-10025MEDIUMCVSS v2 6.8EG 6.82015-01-13
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified users for requests that change the (1) Enable Wireless, (2) MB…
- CVE-2014-10027MEDIUMCVSS v2 6.8EG 6.82015-01-13
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 router with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified users for requests that (1) change the MAC filter restr…
- CVE-2014-10381HIGHCVSS 8.8EG 8.82019-08-20
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
- CVE-2014-10382MEDIUMCVSS 4.3EG 4.32019-08-22
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
- CVE-2014-1211MEDIUMCVSS v2 6.8EG 6.82014-01-17
Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
- CVE-2014-125028HIGHCVSS 4.3EG 8.82022-12-31
A vulnerability was found in valtech IDP Test Client and classified as problematic. Affected by this issue is some unknown functionality of the file python-flask/main.py. The manipulation leads to cross-site request forgery. The attack may…
- CVE-2014-1457HIGHCVSS 8.8EG 8.82018-03-20
Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.
- CVE-2014-1473MEDIUMCVSS v2 6.8EG 6.82014-01-16
Multiple cross-site request forgery (CSRF) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to hijack the authentication of users for requests that modify HTML via uns…
- CVE-2014-1546MEDIUMCVSS v2 4.3EG 4.32014-08-14
The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long call…
- CVE-2014-1615MEDIUMCVSS v2 6.8EG 6.82014-04-22
Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action,…
- CVE-2014-1694MEDIUMCVSS v2 6.8EG 6.82014-02-04
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) CustomerPreferences.pm, (2) CustomerTicketMessage.pm, (3) CustomerTicketProcess.pm, and (4) CustomerTicketZoom.pm in Kernel/Modules/ in Open Ticket Request System (OTRS) 3.1…
- CVE-2014-1915MEDIUMCVSS v2 6.8EG 6.82014-02-07
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the authentication of (1) administrators for requests that change the administrator password vi…
- CVE-2014-1990MEDIUMCVSS v2 6.8EG 6.82014-04-19
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests …
- CVE-2014-2050MEDIUMCVSS 6.5EG 6.52020-01-23
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
- CVE-2014-2115MEDIUMCVSS v2 6.8EG 6.82014-04-04
Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250.
- CVE-2014-2152MEDIUMCVSS v2 6.8EG 6.82015-02-12
Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun21868.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →