CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 22 of 188
- CVE-2015-5170HIGHCVSS 8.8EG 8.82017-10-24
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary…
- CVE-2015-5182HIGHCVSS 8.8EG 8.82017-09-25
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
- CVE-2015-5258HIGHCVSS 8.8EG 8.82017-08-22
Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.
- CVE-2015-5335MEDIUMCVSS 4.3EG 4.32016-02-22
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administra…
- CVE-2015-5338HIGHCVSS 8.8EG 8.82016-02-22
Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary user…
- CVE-2015-5351HIGHCVSS 8.8EG 8.82016-02-25
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a …
- CVE-2015-5395HIGHCVSS 8.8EG 8.82017-09-20
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
- CVE-2015-5445HIGHCVSS 8.8EG 8.82016-01-05
Cross-site request forgery (CSRF) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2015-5483HIGHCVSS 8.8EG 8.82020-01-28
Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modif…
- CVE-2015-5595MEDIUMCVSS 6.5EG 6.52019-12-31
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).
- CVE-2015-5607HIGHCVSS 8.8EG 8.82017-09-20
Cross-site request forgery in the REST API in IPython 2 and 3.
- CVE-2015-5686HIGHCVSS 8.8EG 8.82020-02-27
Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.
- CVE-2015-6541HIGHCVSS 8.8EG 8.82016-04-08
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account prefer…
- CVE-2015-7293HIGHCVSS 8.8EG 8.82017-09-25
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
- CVE-2015-7407HIGHCVSS 8.8EG 8.82016-01-02
Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- CVE-2015-7446HIGHCVSS 8.8EG 8.82016-03-12
Cross-site request forgery (CSRF) vulnerability in IBM Flash System V9000 7.4 before 7.4.1.4, 7.5 before 7.5.1.3, and 7.6 before 7.6.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS s…
- CVE-2015-7465HIGHCVSS 8.8EG 8.82016-01-10
Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for…
- CVE-2015-7537HIGHCVSS 8.8EG 8.82016-02-03
Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP…
- CVE-2015-7563HIGHCVSS 8.8EG 8.82017-04-12
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.
- CVE-2015-7610HIGHCVSS 8.8EG 8.82018-05-30
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authenticati…
- CVE-2015-7678HIGHCVSS 8.8EG 8.82016-02-10
Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2015-7715HIGHCVSS 8.8EG 8.82017-10-18
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to …
- CVE-2015-8152HIGHCVSS 8.0EG 8.02016-03-18
Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by…
- CVE-2015-8255HIGHCVSS 8.8EG 8.82017-04-10
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
- CVE-2015-8379HIGHCVSS 8.8EG 8.82016-01-26
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
- CVE-2015-8536HIGHCVSS 8.8EG 8.82020-03-27
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow cross-site …
- CVE-2015-8623HIGHCVSS 8.8EG 8.82017-03-23
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypa…
- CVE-2015-8624HIGHCVSS 8.8EG 8.82017-03-23
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging m…
- CVE-2015-8814HIGHCVSS 8.8EG 8.82017-03-03
Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.
- CVE-2015-9233HIGHCVSS 8.8EG 8.82017-09-30
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
- CVE-2015-9284HIGHCVSS 8.8EG 8.82019-04-26
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedba…
- CVE-2015-9292HIGHCVSS 8.8EG 8.82019-08-08
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
- CVE-2015-9307HIGHCVSS 8.8EG 8.82019-08-14
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
- CVE-2015-9308HIGHCVSS 8.8EG 8.82019-08-14
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
- CVE-2015-9309HIGHCVSS 8.8EG 8.82019-08-14
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
- CVE-2015-9322HIGHCVSS 8.8EG 8.82019-08-16
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
- CVE-2015-9332MEDIUMCVSS 6.5EG 6.52019-08-20
The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=uninstall URI.
- CVE-2015-9343HIGHCVSS 8.8EG 8.82019-08-27
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
- CVE-2015-9380HIGHCVSS 8.8EG 8.82019-08-30
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
- CVE-2015-9387MEDIUMCVSS 6.5EG 6.52019-09-20
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.
- CVE-2015-9388MEDIUMCVSS 6.5EG 6.52019-09-20
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.
- CVE-2015-9394HIGHCVSS 8.8EG 8.82019-09-20
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
- CVE-2015-9408MEDIUMCVSS 6.5EG 6.52019-09-20
The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS.
- CVE-2015-9409MEDIUMCVSS 6.5EG 6.52019-09-25
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
- CVE-2015-9413MEDIUMCVSS 6.5EG 6.52019-09-26
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
- CVE-2015-9417MEDIUMCVSS 6.5EG 6.52019-09-26
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
- CVE-2015-9418MEDIUMCVSS 4.3EG 4.32019-09-26
The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.
- CVE-2015-9421MEDIUMCVSS 6.5EG 6.52019-09-26
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
- CVE-2015-9422MEDIUMCVSS 6.5EG 6.52019-09-26
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin,…
- CVE-2015-9424MEDIUMCVSS 6.5EG 6.52019-09-26
The multicons plugin before 3.0 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=multicons%2Fmulticons.php global_url or admin_url parameter.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →