CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,376 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 7 of 188
- CVE-2010-3883MEDIUMCVSS v2 6.8EG 6.82010-10-08
Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make permission modificat…
- CVE-2010-3884MEDIUMCVSS v2 6.8EG 6.82010-10-08
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this i…
- CVE-2010-3891MEDIUMCVSS v2 6.8EG 6.82010-11-12
Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that ad…
- CVE-2010-3989MEDIUMCVSS v2 6.8EG 6.82010-10-28
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2010-4024MEDIUMCVSS v2 6.8EG 6.82010-10-28
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2010-4032MEDIUMCVSS v2 6.8EG 6.82010-11-02
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2010-4106MEDIUMCVSS v2 6.8EG 6.82010-11-02
Cross-site request forgery (CSRF) vulnerability in HP Insight Control for Linux before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2010-4241HIGHCVSS 8.8EG 8.82019-10-28
Tiki Wiki CMS Groupware 5.2 has CSRF
- CVE-2010-4507HIGHCVSS v2 9.3EG 9.32010-12-30
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 and R1786, with firmware 1.9.9.4 allow remote attackers to hijack the authentication of administrators for requests that…
- CVE-2010-4519MEDIUMCVSS v2 6.8EG 6.82010-12-23
Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for r…
- CVE-2010-4627MEDIUMCVSS v2 6.8EG 6.82010-12-30
Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) before 1.4.12 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2010-4729MEDIUMCVSS v2 6.8EG 6.82011-02-08
Zikula before 1.2.3 does not use the authid protection mechanism for (1) the lostpassword form and (2) mailpasswd processing, which makes it easier for remote attackers to generate a flood of password requests and possibly conduct cross-si…
- CVE-2010-4750MEDIUMCVSS v2 6.8EG 6.82011-03-01
Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administrators.
- CVE-2010-4881MEDIUMCVSS v2 6.8EG 6.82011-10-07
Multiple cross-site request forgery (CSRF) vulnerabilities in calendar.class.php in ApPHP Calendar (ApPHP CAL) allow remote attackers to hijack the authentication of unspecified victims for requests that use the (1) category_name, (2) cate…
- CVE-2010-5084MEDIUMCVSS v2 6.0EG 6.02012-02-14
The cross-site request forgery (CSRF) protection mechanism in e107 before 0.7.23 uses a predictable random token based on the creation date of the administrator account, which allows remote attackers to hijack the authentication of adminis…
- CVE-2010-5085MEDIUMCVSS v2 6.8EG 6.82012-02-14
Multiple cross-site request forgery (CSRF) vulnerabilities in admin/update_user in Hulihan Amethyst 0.1.5, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the adminis…
- CVE-2010-5088MEDIUMCVSS v2 6.8EG 6.82012-08-26
Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of administrators via destructive controller actions, a different vuln…
- CVE-2010-5191HIGHCVSS v2 9.3EG 9.32012-08-26
Multiple cross-site request forgery (CSRF) vulnerabilities on the Blue Coat ProxyAV appliance before 3.2.6.1 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password, (2) modify a policy…
- CVE-2010-5283MEDIUMCVSS v2 6.8EG 6.82012-11-26
Cross-site request forgery (CSRF) vulnerability in OpenText ECM (formerly Livelink ECM) 9.7.1 allows remote attackers to hijack the authentication of administrators for requests that change folder and resource permissions.
- CVE-2010-5285MEDIUMCVSS v2 6.8EG 6.82012-11-26
Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via the edituser action.
- CVE-2010-5315MEDIUMCVSS v2 6.8EG 6.82015-01-03
Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create categories via a data array to news/saveCategories or (2) mo…
- CVE-2010-5319MEDIUMCVSS v2 6.8EG 6.82015-01-03
Multiple cross-site request forgery (CSRF) vulnerabilities in Kandidat CMS 1.4.2 allow remote attackers to hijack the authentication of administrators for requests that (1) modify settings via a validate action to admin/settings.php, (2) m…
- CVE-2010-5320MEDIUMCVSS v2 6.8EG 6.82015-01-03
Multiple cross-site request forgery (CSRF) vulnerabilities in MemHT Portal 4.0.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify settings via a configuration action to admin.php, (2) modif…
- CVE-2011-0046MEDIUMCVSS v2 6.8EG 6.82011-01-28
Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 allow remote attackers to hijack the authentication of arbitrary users for requests rela…
- CVE-2011-0059MEDIUMCVSS v2 6.8EG 6.82011-03-02
Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated…
- CVE-2011-0277MEDIUMCVSS v2 6.8EG 6.82011-02-09
Cross-site request forgery (CSRF) vulnerability in HP Power Manager (HPPM) 4.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.
- CVE-2011-0440MEDIUMCVSS v2 5.8EG 5.82011-03-28
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.
- CVE-2011-0503MEDIUMCVSS v2 6.8EG 6.82011-01-20
Cross-site request forgery (CSRF) vulnerability in VaM Shop 1.6, 1.6.1, and probably earlier versions allows remote attackers to hijack the authentication of administrators for requests that (1) change user status via admin/customers.php o…
- CVE-2011-0525HIGHCVSS 8.8EG 8.82020-02-05
Batavi before 1.0 has CSRF.
- CVE-2011-0535MEDIUMCVSS v2 6.8EG 6.82011-02-08
Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change account privileges via an edit access_permissions ac…
- CVE-2011-0545MEDIUMCVSS v2 6.8EG 6.82011-03-28
Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts…
- CVE-2011-0551MEDIUMCVSS v2 6.8EG 6.82011-08-15
Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allows remote attackers to hijack the authentication of administrator…
- CVE-2011-0629MEDIUMCVSS v2 6.8EG 6.82011-06-16
Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2011-0642MEDIUMCVSS v2 4.3EG 4.32011-01-25
Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some …
- CVE-2011-0643MEDIUMCVSS v2 6.8EG 6.82011-01-25
Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.
- CVE-2011-0650MEDIUMCVSS v2 6.8EG 6.82011-01-28
Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the authentication of users for requests that send email via an OMP request to OpenVAS Manager. NOTE: t…
- CVE-2011-0746MEDIUMCVSS v2 4.3EG 4.32011-04-13
Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) se…
- CVE-2011-0748MEDIUMCVSS v2 6.8EG 6.82011-04-13
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit administrator accounts.
- CVE-2011-0759MEDIUMCVSS v2 6.8EG 6.82011-03-22
Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka WP-reCAPTCHA) plugin 2.9.8.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that d…
- CVE-2011-0760MEDIUMCVSS v2 4.3EG 4.32011-03-28
Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.php in the WP Related Posts plugin 1.0 for WordPress allow remote attackers to hijack the authentication of administrators for reques…
- CVE-2011-0886MEDIUMCVSS v2 6.8EG 6.82011-02-08
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 allow remote attackers to (1) hijack the intranet connectivity of arbitrar…
- CVE-2011-1026MEDIUMCVSS v2 6.8EG 6.82011-06-02
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to hijack the authentication of administrators.
- CVE-2011-1085HIGHCVSS 8.8EG 8.82020-02-07
CSRF vulnerability in Smoothwall Express 3.
- CVE-2011-1104MEDIUMCVSS v2 6.8EG 6.82011-02-28
Multiple cross-site request forgery (CSRF) vulnerabilities in Mutare EVM allow remote attackers to hijack the authentication of arbitrary users for requests that (1) change a PIN, (2) delete messages, (3) add a delivery address, or (4) cha…
- CVE-2011-1324MEDIUMCVSS v2 5.8EG 5.82011-05-09
Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote att…
- CVE-2011-1325MEDIUMCVSS v2 5.8EG 5.82011-05-13
Cross-site request forgery (CSRF) vulnerability in EC-CUBE before 2.11.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2011-1341MEDIUMCVSS v2 6.8EG 6.82011-08-19
Cross-site request forgery (CSRF) vulnerability in Aimluck Aipo before 4.0.4.0, and Aipo for ASP before 4.0.4.0, allows remote attackers to hijack the authentication of administrators for requests that modify data.
- CVE-2011-1364MEDIUMCVSS v2 6.8EG 6.82011-10-30
Cross-site request forgery (CSRF) vulnerability in _ah/admin/interactive/execute (aka the Interactive Console) in the SDK Console (aka Admin Console) in the Google App Engine Python SDK before 1.5.4 allows remote attackers to hijack the au…
- CVE-2011-1397MEDIUMCVSS v2 6.8EG 6.82012-03-13
Cross-site request forgery (CSRF) vulnerability in the Labor Reporting page in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request …
- CVE-2011-1403MEDIUMCVSS v2 6.8EG 6.82011-05-13
Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentication of arbitrary users for requests to any form, related to inappropriate regeneration o…
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →