CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 23 of 188
- CVE-2015-9425MEDIUMCVSS 5.4EG 5.42019-09-26
The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.
- CVE-2015-9427MEDIUMCVSS 6.5EG 6.52019-09-26
The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID or AID parameter.
- CVE-2015-9428MEDIUMCVSS 6.5EG 6.52019-09-26
The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parame…
- CVE-2015-9429MEDIUMCVSS 6.5EG 6.52019-09-26
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.
- CVE-2015-9431MEDIUMCVSS 6.5EG 6.52019-09-26
The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.
- CVE-2015-9432MEDIUMCVSS 6.5EG 6.52019-09-26
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
- CVE-2015-9433MEDIUMCVSS 6.5EG 6.52019-09-26
The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fad…
- CVE-2015-9434MEDIUMCVSS 6.5EG 6.52019-09-26
The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter.
- CVE-2015-9437MEDIUMCVSS 6.5EG 6.52019-09-26
The dynamic-widgets plugin before 1.5.11 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=dynwid-config page_limit parameter.
- CVE-2015-9440MEDIUMCVSS 6.5EG 6.52019-09-26
The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.
- CVE-2015-9441MEDIUMCVSS 6.5EG 6.52019-09-26
The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.
- CVE-2015-9442MEDIUMCVSS 6.5EG 6.52019-09-26
The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.
- CVE-2015-9443MEDIUMCVSS 6.5EG 6.52019-09-26
The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.
- CVE-2015-9445HIGHCVSS 8.8EG 8.82019-09-26
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
- CVE-2015-9447MEDIUMCVSS 6.5EG 6.52019-09-26
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
- CVE-2015-9455HIGHCVSS 8.1EG 8.12019-10-07
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
- CVE-2015-9497HIGHCVSS 8.8EG 8.82019-10-22
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
- CVE-2015-9498HIGHCVSS 8.8EG 8.82019-10-22
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
- CVE-2016-0272HIGHCVSS 8.0EG 8.02018-03-09
Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1…
- CVE-2016-0295HIGHCVSS 8.8EG 8.82018-02-28
Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: …
- CVE-2016-0335HIGHCVSS 8.8EG 8.82018-01-12
Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that h…
- CVE-2016-0348HIGHCVSS 8.0EG 8.02018-02-21
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: …
- CVE-2016-0355MEDIUMCVSS 6.5EG 6.52017-08-29
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 11…
- CVE-2016-0356MEDIUMCVSS 6.5EG 6.52017-08-29
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 11…
- CVE-2016-0386HIGHCVSS 8.0EG 8.02016-07-02
Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to hijack the authentication of administrators for request…
- CVE-2016-0720HIGHCVSS 8.8EG 8.82017-04-21
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
- CVE-2016-0863HIGHCVSS 8.8EG 8.82016-02-13
Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to hijack the authentication of arbitrary users.
- CVE-2016-0891HIGHCVSS 8.8EG 8.82016-04-20
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remote attackers to hijack the authentication of administrators.
- CVE-2016-0948HIGHCVSS 8.8EG 8.82016-02-10
Cross-site request forgery (CSRF) vulnerability in Adobe Connect before 9.5.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2016-1000213HIGHCVSS 8.8EG 8.82016-10-25
Ruckus Wireless H500 web management interface CSRF
- CVE-2016-1000218HIGHCVSS 8.8EG 8.82017-06-16
Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially-crafted page.
- CVE-2016-10206HIGHCVSS 8.8EG 8.82017-03-03
Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a…
- CVE-2016-10313HIGHCVSS 8.8EG 8.82017-04-03
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct CSRF attacks via certain /goform/* pa…
- CVE-2016-10522HIGHCVSS 8.8EG 8.82018-07-05
rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpo…
- CVE-2016-10529HIGHCVSS 8.8EG 8.82018-05-31
Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this mean…
- CVE-2016-10701HIGHCVSS 8.8EG 8.82017-11-28
In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.
- CVE-2016-10738HIGHCVSS 8.8EG 8.82019-01-16
Zenbership v107 has CSRF via admin/cp-functions/event-add.php.
- CVE-2016-10756HIGHCVSS 8.8EG 8.82019-05-24
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.
- CVE-2016-10757HIGHCVSS 8.8EG 8.82019-05-24
In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.
- CVE-2016-10766HIGHCVSS 8.8EG 8.82019-07-29
edx-platform before 2016-06-06 allows CSRF.
- CVE-2016-10861MEDIUMCVSS 6.5EG 6.52019-08-07
Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.
- CVE-2016-10862HIGHCVSS 8.8EG 8.82019-08-08
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
- CVE-2016-10863HIGHCVSS 8.8EG 8.82019-08-08
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
- CVE-2016-10865MEDIUMCVSS 6.1EG 6.12019-08-09
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS.
- CVE-2016-10874HIGHCVSS 8.8EG 8.82019-08-12
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
- CVE-2016-10876HIGHCVSS 8.8EG 8.82019-08-12
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
- CVE-2016-10882HIGHCVSS 8.8EG 8.82019-08-14
The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
- CVE-2016-10883MEDIUMCVSS 6.5EG 6.52019-08-14
The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.
- CVE-2016-10884HIGHCVSS 8.8EG 8.82019-08-14
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
- CVE-2016-10885HIGHCVSS 8.8EG 8.82019-08-14
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →