CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 29 of 188
- CVE-2017-16570HIGHCVSS 8.8EG 8.82017-11-06
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header.
- CVE-2017-1672HIGHCVSS 8.8EG 8.82018-01-04
IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133639.
- CVE-2017-16756HIGHCVSS 8.8EG 8.82018-02-19
An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's…
- CVE-2017-16780CRITICALCVSS 9.8EG 9.82017-11-10
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
- CVE-2017-16862MEDIUMCVSS 4.3EG 4.32018-01-12
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.
- CVE-2017-16886HIGHCVSS 8.8EG 8.82018-01-12
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or pass…
- CVE-2017-17056HIGHCVSS 8.8EG 8.82017-12-04
The ZKTime Web Software 2.0.1.12280 allows the Administrator to elevate the privileges of the application user using a 'password_change()' function of the Modify Password component, reachable via the old_password, new_password1, and new_pa…
- CVE-2017-1746HIGHCVSS 8.8EG 8.82017-12-20
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Fo…
- CVE-2017-17550HIGHCVSS 8.8EG 8.82018-11-10
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently be used for stored XSS.
- CVE-2017-17552HIGHCVSS 8.8EG 8.82018-02-07
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
- CVE-2017-1769HIGHCVSS 8.8EG 8.82018-01-24
IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.
- CVE-2017-17774HIGHCVSS 8.8EG 8.82017-12-20
admin/configuration.php in Piwigo 2.9.2 has CSRF.
- CVE-2017-17827HIGHCVSS 8.8EG 8.82017-12-21
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.
- CVE-2017-17830MEDIUMCVSS 6.8EG 6.82017-12-21
Bus Booking Script has CSRF via admin/new_master.php.
- CVE-2017-17835HIGHCVSS 8.8EG 8.82019-01-23
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
- CVE-2017-17891HIGHCVSS 8.8EG 8.82017-12-27
Readymade Video Sharing Script has CSRF via user-profile-edit.php.
- CVE-2017-17894HIGHCVSS 8.8EG 8.82017-12-27
Readymade Job Site Script has CSRF via the /job URI.
- CVE-2017-17903HIGHCVSS 8.8EG 8.82017-12-27
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
- CVE-2017-17905HIGHCVSS 8.8EG 8.82017-12-27
PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.
- CVE-2017-17908HIGHCVSS 8.8EG 8.82017-12-27
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.
- CVE-2017-17930HIGHCVSS 8.8EG 8.82017-12-27
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.
- CVE-2017-17936HIGHCVSS 8.8EG 8.82017-12-28
Vanguard Marketplace Digital Products PHP has CSRF via /search.
- CVE-2017-17939HIGHCVSS 8.8EG 8.82017-12-28
PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.
- CVE-2017-17960HIGHCVSS 8.8EG 8.82017-12-28
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
- CVE-2017-17982MEDIUMCVSS 6.8EG 6.82017-12-30
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
- CVE-2017-17990HIGHCVSS 8.8EG 8.82017-12-30
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.
- CVE-2017-18033MEDIUMCVSS 6.5EG 6.52018-01-18
The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.
- CVE-2017-18042HIGHCVSS 8.8EG 8.82018-02-02
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
- CVE-2017-18080HIGHCVSS 8.8EG 8.82018-02-02
The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
- CVE-2017-18107MEDIUMCVSS 6.5EG 6.52019-12-17
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the …
- CVE-2017-18366HIGHCVSS 8.8EG 8.82019-04-15
Subrion CMS 4.1.5 has CSRF in blog/delete/.
- CVE-2017-18485MEDIUMCVSS 5.4EG 5.42019-08-08
Cognitoys Dino devices allow profiles_add.html CSRF.
- CVE-2017-18504HIGHCVSS 8.8EG 8.82019-08-12
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
- CVE-2017-18510HIGHCVSS 8.8EG 8.82019-08-14
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.
- CVE-2017-18511HIGHCVSS 8.8EG 8.82019-08-14
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
- CVE-2017-18512HIGHCVSS 8.8EG 8.82019-08-14
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
- CVE-2017-18513HIGHCVSS 8.8EG 8.82019-08-14
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
- CVE-2017-18521HIGHCVSS 8.8EG 8.82019-08-21
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.
- CVE-2017-18523HIGHCVSS 8.8EG 8.82019-08-20
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
- CVE-2017-18544HIGHCVSS 8.8EG 8.82019-08-16
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
- CVE-2017-18546HIGHCVSS 8.8EG 8.82019-08-16
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
- CVE-2017-18547HIGHCVSS 8.8EG 8.82019-08-16
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
- CVE-2017-18569HIGHCVSS 8.8EG 8.82019-08-20
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
- CVE-2017-18607HIGHCVSS 8.8EG 8.82019-09-10
The avada theme before 5.1.5 for WordPress has CSRF.
- CVE-2017-18703HIGHCVSS 8.8EG 8.82020-04-24
Certain NETGEAR devices are affected by CSRF. This affects D1500 before 1.0.0.25, D500 before 1.0.0.25, D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, EX6100v2 before 1.0.1.60, EX6150v2 before 1.0.1.60, JNR1010v2 befo…
- CVE-2017-18708HIGHCVSS 8.8EG 8.82020-04-24
Certain NETGEAR devices are affected by CSRF. This affects R8300 before 1.0.2.94 and R8500 before 1.0.2.94.
- CVE-2017-18742HIGHCVSS 8.8EG 8.82020-04-23
Certain NETGEAR devices are affected by CSRF. This affects JR6150 before 1.0.1.10, R6050 before 1.0.1.10, R6250 before 1.0.4.12, R6300v2 before 1.0.4.8, R6700 before 1.0.1.16, R6900 before 1.0.1.16, R7300DST before 1.0.0.54, R7900 before 1…
- CVE-2017-18749HIGHCVSS 8.8EG 8.82020-04-23
Certain NETGEAR devices are affected by CSRF. This affects JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, R6050 before 1.0.1.10, R6100 before 1.0.1.16, R6220 before 1.1.0.50, R7500 before 1.0.0.112, R7500v2 …
- CVE-2017-18755HIGHCVSS 8.8EG 8.82020-04-22
Certain NETGEAR devices are affected by CSRF. This affects R6300v2 before 1.0.4.8, R6400v2 before 1.0.2.32, R6700 before 1.0.1.22, R6900 before 1.0.1.22, R7000P before 1.0.0.86, R6900P before 1.0.0.56, R7300 before 1.0.0.54, R8300 before 1…
- CVE-2017-18768HIGHCVSS 8.8EG 8.82020-04-22
Certain NETGEAR devices are affected by CSRF. This affects EX6100 before 1.0.2.16_1.1.130, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.54, EX6200v2 before 1.0.1.50, EX6400 before 1.0.1.60, EX7300 before 1.0.1.60, and WN3000RPv3 before …
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →