CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 20 of 188
- CVE-2014-9344MEDIUMCVSS v2 6.8EG 6.82014-12-08
Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators for requests that add a new admin account via a submit action in the admin/accounts/create …
- CVE-2014-9368MEDIUMCVSS v2 6.8EG 6.82014-12-19
Cross-site request forgery (CSRF) vulnerability in the twitterDash plugin 2.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via…
- CVE-2014-9382MEDIUMCVSS 6.5EG 6.52020-01-13
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
- CVE-2014-9385MEDIUMCVSS v2 6.8EG 6.82014-12-15
Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger arbitrary code execution via a ZenPack upload, aka ZEN-15388.
- CVE-2014-9391MEDIUMCVSS v2 6.8EG 6.82014-12-31
Multiple cross-site request forgery (CSRF) vulnerabilities in the gSlideShow plugin 0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) at…
- CVE-2014-9392MEDIUMCVSS v2 6.8EG 6.82014-12-31
Cross-site request forgery (CSRF) vulnerability in the PictoBrowser (pictobrowser-gallery) plugin 0.3.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site s…
- CVE-2014-9393MEDIUMCVSS v2 6.8EG 6.82014-12-31
Multiple cross-site request forgery (CSRF) vulnerabilities in the Post to Twitter plugin 0.7 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XS…
- CVE-2014-9394MEDIUMCVSS v2 6.8EG 6.82014-12-31
Multiple cross-site request forgery (CSRF) vulnerabilities in the PWGRandom plugin 1.11 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) at…
- CVE-2014-9395MEDIUMCVSS v2 6.8EG 6.82014-12-31
Multiple cross-site request forgery (CSRF) vulnerabilities in the Simplelife plugin 1.2 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) at…
- CVE-2014-9396MEDIUMCVSS v2 6.8EG 6.82014-12-31
Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleFlickr plugin 3.0.3 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS…
- CVE-2014-9397MEDIUMCVSS v2 6.8EG 6.82014-12-31
Cross-site request forgery (CSRF) vulnerability in the twimp-wp plugin for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the message_format…
- CVE-2014-9398MEDIUMCVSS v2 6.8EG 6.82014-12-31
Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) atta…
- CVE-2014-9399MEDIUMCVSS v2 6.8EG 6.82014-12-31
Cross-site request forgery (CSRF) vulnerability in the TweetScribe plugin 1.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via…
- CVE-2014-9400MEDIUMCVSS v2 6.8EG 6.82014-12-31
Multiple cross-site request forgery (CSRF) vulnerabilities in the Wp Unique Article Header Image plugin 1.0 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-sit…
- CVE-2014-9401MEDIUMCVSS v2 6.8EG 6.82014-12-31
Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting …
- CVE-2014-9407MEDIUMCVSS v2 6.8EG 6.82014-12-19
Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) delete data via a request to agency-delete.php, (2) trac…
- CVE-2014-9413MEDIUMCVSS v2 6.8EG 6.82014-12-24
Multiple cross-site request forgery (CSRF) vulnerabilities in the IP Ban (simple-ip-ban) plugin 1.2.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) …
- CVE-2014-9414MEDIUMCVSS v2 6.8EG 6.82014-12-24
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests t…
- CVE-2014-9431MEDIUMCVSS v2 6.8EG 6.82014-12-31
Multiple cross-site request forgery (CSRF) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to hijack the authentication of administrators for requests that change the (1) admin or (2) dial password via a reques…
- CVE-2014-9437MEDIUMCVSS v2 6.8EG 6.82015-01-02
Multiple cross-site request forgery (CSRF) vulnerabilities in the Sliding Social Icons plugin 1.61 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspeci…
- CVE-2014-9438MEDIUMCVSS v2 6.8EG 6.82015-01-02
Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the authentication of administrators for requests that (1) ban a user via the username parameter in a doban…
- CVE-2014-9441MEDIUMCVSS v2 6.8EG 6.82015-01-02
Multiple cross-site request forgery (CSRF) vulnerabilities in the Lightbox Photo Gallery plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspec…
- CVE-2014-9454MEDIUMCVSS v2 6.8EG 6.82015-01-02
Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Sticky Footer plugin before 1.3.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via…
- CVE-2014-9459MEDIUMCVSS v2 6.8EG 6.82015-01-02
Cross-site request forgery (CSRF) vulnerability in the AdminObserver function in e107_admin/users.php in e107 2.0 alpha2 allows remote attackers to hijack the authentication of administrators for requests that add users to the administrato…
- CVE-2014-9460MEDIUMCVSS v2 6.8EG 6.82015-01-02
Multiple cross-site request forgery (CSRF) vulnerabilities in the WP-ViperGB plugin before 1.3.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecif…
- CVE-2014-9502HIGHCVSS 8.8EG 8.82018-02-01
Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allow remote attackers to hijack the authentication of unknown victims via vectors related t…
- CVE-2014-9510MEDIUMCVSS v2 6.8EG 6.82015-01-09
Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141120 allows remote attackers to hijack the authentication of administrators for requests th…
- CVE-2014-9523MEDIUMCVSS v2 6.8EG 6.82015-01-05
Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plug…
- CVE-2014-9524MEDIUMCVSS v2 6.8EG 6.82015-01-05
Multiple cross-site request forgery (CSRF) vulnerabilities in the Facebook Like Box (cardoza-facebook-like-box) plugin before 2.8.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) c…
- CVE-2014-9525MEDIUMCVSS v2 6.8EG 6.82015-01-05
Multiple cross-site request forgery (CSRF) vulnerabilities in the Timed Popup (wp-timed-popup) plugin 1.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via …
- CVE-2014-9565HIGHCVSS 8.8EG 8.82017-09-07
Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earlier.
- CVE-2014-9587MEDIUMCVSS v2 6.8EG 6.82015-01-15
Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) …
- CVE-2014-9694HIGHCVSS 8.8EG 8.82017-04-02
Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal…
- CVE-2015-0151HIGHCVSS 8.8EG 8.82018-04-12
Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- CVE-2015-0276HIGHCVSS 8.8EG 8.82017-09-21
Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2.
- CVE-2015-0588MEDIUMCVSS v2 6.8EG 6.82015-01-15
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo77055.
- CVE-2015-0596MEDIUMCVSS v2 6.8EG 6.82015-02-02
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj67163.
- CVE-2015-0651MEDIUMCVSS v2 6.8EG 6.82015-02-27
Cross-site request forgery (CSRF) vulnerability in the web GUI in Cisco Application Networking Manager (ANM), and Device Manager (DM) on Cisco 4710 Application Control Engine (ACE) appliances, allows remote attackers to hijack the authenti…
- CVE-2015-0807MEDIUMCVSS v2 6.8EG 6.82015-04-01
The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote att…
- CVE-2015-0895MEDIUMCVSS v2 6.8EG 6.82015-03-07
Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not…
- CVE-2015-0920MEDIUMCVSS v2 6.8EG 6.82015-01-08
Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via …
- CVE-2015-0985MEDIUMCVSS v2 6.8EG 6.82015-03-31
Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of admins for requests that modify the default user's password via a GET request.
- CVE-2015-10001MEDIUMCVSS 4.3EG 4.32021-11-01
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scri…
- CVE-2015-10081HIGHCVSS 4.3EG 8.82023-02-20
A vulnerability was found in arnoldle submitByMailPlugin 1.0b2.9 and classified as problematic. This issue affects some unknown processing of the file edit_list.php. The manipulation leads to cross-site request forgery. The attack may be i…
- CVE-2015-10108MEDIUMCVSS 4.3EG 4.32023-05-31
A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this issue is the function displayShortcode of the file inline-gdocs-viewer.php. The manipulati…
- CVE-2015-10109MEDIUMCVSS 4.3EG 4.32023-06-01
A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the file wp-media-cincopa.php. The manipulation leads to cro…
- CVE-2015-10116MEDIUMCVSS 4.3EG 4.32023-06-06
A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The…
- CVE-2015-10125MEDIUMCVSS 4.3EG 4.32023-10-05
A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remot…
- CVE-2015-10130MEDIUMCVSS 5.3EG 5.32024-03-13
The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circle_thumbnail_slider_with_lightbox_image_management_…
- CVE-2015-1374MEDIUMCVSS v2 6.8EG 6.82015-01-27
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests that conduct (1) cross-site scripting (XSS), (2) SQL inject…
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →