CWE-352— Cross-Site Request Forgery (CSRF)
8,648 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 39 of 173
- CVE-2019-16706HIGHCVSS 8.8EG 8.82019-09-23
kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php.
- CVE-2019-16719MEDIUMCVSS 6.5EG 6.52019-09-23
WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.
- CVE-2019-16721MEDIUMCVSS 6.5EG 6.52019-09-23
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
- CVE-2019-16752MEDIUMCVSS 4.3EG 4.32019-12-04
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious thr…
- CVE-2019-16993HIGHCVSS 8.8EG 8.82019-09-30
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session…
- CVE-2019-17118HIGHCVSS 8.8EG 8.82019-10-17
A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or delete admin users; (2) create or delete groups; or (3) create…
- CVE-2019-1713HIGHCVSS 8.1EG 8.82019-05-03
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vuln…
- CVE-2019-17217HIGHCVSS 8.8EG 8.82019-10-06
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF protection established on the web service.
- CVE-2019-1722MEDIUMCVSS 6.5EG 6.52019-04-18
A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbi…
- CVE-2019-17237HIGHCVSS 8.8EG 8.82019-11-12
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
- CVE-2019-17367HIGHCVSS 8.8EG 8.82019-10-18
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin…
- CVE-2019-17369MEDIUMCVSS 6.5EG 6.52019-10-09
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.
- CVE-2019-17386HIGHCVSS 8.8EG 8.82019-10-10
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
- CVE-2019-17431HIGHCVSS 8.8EG 8.82019-10-10
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.
- CVE-2019-17432MEDIUMCVSS 6.5EG 6.52019-10-10
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.
- CVE-2019-17495CRITICALCVSS 9.8EG 9.82019-10-10
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF tok…
- CVE-2019-17521MEDIUMCVSS 6.5EG 6.52019-10-12
An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI,
- CVE-2019-17590HIGHCVSS 8.8EG 8.82019-11-26
The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote attacker can exploit this by crafting a malicious page and disp…
- CVE-2019-17593HIGHCVSS 8.8EG 8.82019-10-14
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
- CVE-2019-17600CRITICALCVSS 9.8EG 9.82019-10-15
Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user is mishandled.
- CVE-2019-17633HIGHCVSS 8.8EG 8.82019-12-19
For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a publ…
- CVE-2019-1764HIGHCVSS 8.1EG 8.82019-03-22
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The v…
- CVE-2019-17642HIGHCVSS 8.8EG 8.82020-03-05
An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscov…
- CVE-2019-17653HIGHCVSS 8.8EG 8.82020-03-12
A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to perform arbitrary actions using an authenticated user's session by persuading the victim …
- CVE-2019-17675HIGHCVSS 8.8EG 8.82019-10-17
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
- CVE-2019-17676HIGHCVSS 8.8EG 8.82019-10-17
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.
- CVE-2019-1797HIGHCVSS 8.8EG 8.82019-04-18
A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on th…
- CVE-2019-18206HIGHCVSS 8.8EG 8.82019-10-30
A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.
- CVE-2019-18220HIGHCVSS 8.8EG 8.82019-10-23
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be …
- CVE-2019-18271HIGHCVSS 8.8EG 8.82020-01-15
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.
- CVE-2019-18280HIGHCVSS 8.8EG 8.82019-10-23
Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code via a crafted HTML…
- CVE-2019-18346HIGHCVSS 8.8EG 8.82019-12-04
A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administr…
- CVE-2019-18376MEDIUMCVSS 5.9EG 5.92020-04-10
A CSRF token disclosure vulnerability allows a remote attacker, with access to an authenticated Management Center (MC) user's web browser history or a network device that intercepts/logs traffic to MC, to obtain CSRF tokens and use them to…
- CVE-2019-18411HIGHCVSS 8.8EG 8.82019-11-06
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unin…
- CVE-2019-18414HIGHCVSS 8.8EG 8.82019-10-24
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbi…
- CVE-2019-1857MEDIUMCVSS 6.1EG 6.12019-05-03
A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. T…
- CVE-2019-18650HIGHCVSS 8.8EG 8.82019-11-06
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
- CVE-2019-18651MEDIUMCVSS 6.5EG 6.52019-11-14
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML docume…
- CVE-2019-18677MEDIUMCVSS 6.1EG 6.12019-11-26
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inapp…
- CVE-2019-1874HIGHCVSS 8.8EG 8.82019-06-20
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is…
- CVE-2019-1881MEDIUMCVSS 4.7EG 8.82019-06-05
A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affe…
- CVE-2019-18884HIGHCVSS 8.8EG 8.82019-11-13
index.php/team_members/add_team_member in RISE Ultimate Project Manager 2.3 has CSRF for adding authorized users.
- CVE-2019-19013HIGHCVSS 8.8EG 8.82019-11-22
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
- CVE-2019-19025HIGHCVSS 8.8EG 8.82020-03-20
Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.
- CVE-2019-1904HIGHCVSS 8.8EG 8.82019-06-21
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSR…
- CVE-2019-19109HIGHCVSS 8.8EG 8.82020-06-15
The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
- CVE-2019-1915MEDIUMCVSS 6.5EG 6.52019-10-02
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, …
- CVE-2019-19289HIGHCVSS 8.8EG 8.82020-12-14
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link.
- CVE-2019-19375MEDIUMCVSS 5.3EG 5.32019-11-28
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
- CVE-2019-19469HIGHCVSS 8.8EG 8.82019-12-01
In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →