CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,376 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 8 of 188
- CVE-2011-1482MEDIUMCVSS v2 6.8EG 6.82011-06-21
Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts or (2) gra…
- CVE-2011-1543MEDIUMCVSS v2 4.3EG 4.32011-04-29
Cross-site request forgery (CSRF) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2011-1545MEDIUMCVSS v2 6.8EG 6.82011-05-03
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2011-1664MEDIUMCVSS v2 6.8EG 6.82011-04-10
Cross-site request forgery (CSRF) vulnerability in the Translation Management module 6.x before 6.x-1.21 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2011-1682MEDIUMCVSS v2 4.3EG 4.32011-04-13
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) se…
- CVE-2011-1685MEDIUMCVSS v2 4.6EG 4.62011-04-22
Best Practical Solutions RT 3.8.0 through 3.8.9 and 4.0.0rc through 4.0.0rc7, when the CustomFieldValuesSources (aka external custom field) option is enabled, allows remote authenticated users to execute arbitrary code via unspecified vect…
- CVE-2011-1721MEDIUMCVSS v2 4.3EG 4.32011-04-19
Cross-site request forgery (CSRF) vulnerability in php/partie_administrateur/administration.php in WebJaxe 1.02 allows remote attackers to hijack the authentication of administrators for requests that (1) modify passwords or (2) add new pr…
- CVE-2011-1905MEDIUMCVSS v2 6.8EG 6.82011-05-05
Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified administrative modules in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, an…
- CVE-2011-1911MEDIUMCVSS v2 6.8EG 6.82011-09-20
JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approa…
- CVE-2011-1954MEDIUMCVSS v2 6.8EG 6.82011-06-06
Multiple cross-site request forgery (CSRF) vulnerabilities in Post Revolution 0.8.0c-2 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests to (1) ajax-weblog-guardar.php, (2) verpost.php, (3) com…
- CVE-2011-2085MEDIUMCVSS v2 6.8EG 6.82012-06-04
Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote attackers to hijack the authentication of arbitrary users.
- CVE-2011-2191MEDIUMCVSS v2 6.8EG 6.82011-10-07
Cross-site request forgery (CSRF) vulnerability in Cherokee-admin in Cherokee before 1.2.99 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, as demonstrat…
- CVE-2011-2522MEDIUMCVSS v2 6.8EG 6.82011-07-29
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1) shut down daemons…
- CVE-2011-2753MEDIUMCVSS v2 6.8EG 6.82011-07-17
Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.21 and earlier allow remote attackers to hijack the authentication of unspecified victims via vectors involving (1) the empty trash implementation and (2) the I…
- CVE-2011-2773MEDIUMCVSS v2 6.8EG 6.82011-11-15
Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for requests that add a user to an institution.
- CVE-2011-2908MEDIUMCVSS v2 6.0EG 6.02012-11-23
Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijac…
- CVE-2011-2934HIGHCVSS 8.8EG 8.82020-01-14
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.
- CVE-2011-3293MEDIUMCVSS v2 6.8EG 6.82012-05-02
Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scr…
- CVE-2011-3381MEDIUMCVSS v2 6.8EG 6.82011-09-08
Cross-site request forgery (CSRF) vulnerability in Phorum before 5.2.16 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2011-3582HIGHCVSS 8.8EG 8.82020-01-22
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
- CVE-2011-3609MEDIUMCVSS 6.5EG 6.52019-11-26
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to …
- CVE-2011-3612HIGHCVSS 8.8EG 8.82020-01-22
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
- CVE-2011-3636MEDIUMCVSS v2 6.8EG 6.82011-12-08
Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of administrators for requests that make configuration changes.
- CVE-2011-3668MEDIUMCVSS v2 6.8EG 6.82012-01-02
Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that create bug reports.
- CVE-2011-3669MEDIUMCVSS v2 6.8EG 6.82012-01-02
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the authentication of arbitrary users for requests that upload attachments.
- CVE-2011-3836MEDIUMCVSS v2 6.8EG 6.82011-12-24
Multiple cross-site request forgery (CSRF) vulnerabilities in Wuzly 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator, (2) perform cross-site scripting (XSS), (3) perform S…
- CVE-2011-3846MEDIUMCVSS v2 6.8EG 6.82012-04-12
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
- CVE-2011-3994MEDIUMCVSS v2 6.8EG 6.82011-11-03
Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type…
- CVE-2011-4005HIGHCVSS v2 9.3EG 9.32011-11-03
Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521W, SRP526W, and SRP527W with firmware before 1.1.24 and the Small Business SRP541W, SRP546…
- CVE-2011-4140HIGHCVSS v2 6.8EG 7.52011-10-19
The CSRF protection mechanism in Django through 1.2.7 and 1.3.x through 1.3.1 does not properly handle web-server configurations supporting arbitrary HTTP Host headers, which allows remote attackers to trigger unauthenticated forged reques…
- CVE-2011-4173MEDIUMCVSS v2 6.8EG 6.82011-10-24
Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication of administrators or moderators via vectors involving image files, a different vulnerabili…
- CVE-2011-4452MEDIUMCVSS v2 6.8EG 6.82012-09-05
Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authentication of administrators for requests that remove arbitrary user accounts via a delete o…
- CVE-2011-4498MEDIUMCVSS v2 6.8EG 6.82011-11-21
Cross-site request forgery (CSRF) vulnerability in the web console in Zenprise Device Manager 6.x through 6.1.8 allows remote attackers to hijack the authentication of administrators for requests that wipe mobile devices.
- CVE-2011-4642MEDIUMCVSS v2 4.6EG 4.62012-01-03
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a …
- CVE-2011-4837MEDIUMCVSS v2 6.8EG 6.82011-12-15
Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to hijack the authentication of admins for requests that execute arbitrary programs.
- CVE-2011-4947MEDIUMCVSS v2 6.8EG 6.82012-08-31
Cross-site request forgery (CSRF) vulnerability in e107_admin/users_extended.php in e107 before 0.7.26 allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via…
- CVE-2011-4952HIGHCVSS 8.8EG 8.82019-11-19
cobbler: Web interface lacks CSRF protection when using Django framework
- CVE-2011-5011MEDIUMCVSS v2 6.8EG 6.82011-12-25
Multiple cross-site request forgery (CSRF) vulnerabilities in xt:Commerce 3.0.4 SP2.1 and possibly earlier allow remote attackers to hijack the authentication of Admins for requests that (1) set a New user to Admin via the cID parameter to…
- CVE-2011-5068MEDIUMCVSS v2 6.8EG 6.82012-01-29
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the authentication of user for requests that delete a user via user_delete.php and other unspecified pr…
- CVE-2011-5074MEDIUMCVSS v2 6.8EG 6.82012-01-29
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new adm…
- CVE-2011-5131MEDIUMCVSS v2 6.8EG 6.82012-08-30
Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user's language via the language parameter.
- CVE-2011-5195MEDIUMCVSS v2 6.8EG 6.82012-09-23
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that uplo…
- CVE-2011-5196MEDIUMCVSS v2 6.8EG 6.82012-09-23
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload …
- CVE-2011-5197MEDIUMCVSS v2 6.8EG 6.82012-09-23
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that uploa…
- CVE-2011-5226MEDIUMCVSS v2 6.8EG 6.82012-10-25
Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an administrator for requests that trigger snapshots.
- CVE-2011-5250MEDIUMCVSS 6.5EG 6.52020-01-08
Snare for Linux before 1.7.0 has CSRF in the web interface.
- CVE-2011-5284MEDIUMCVSS v2 6.8EG 6.82014-12-31
Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requ…
- CVE-2011-5298MEDIUMCVSS v2 6.8EG 6.82015-01-01
Multiple cross-site request forgery (CSRF) vulnerabilities in Argyle Social 2011-04-26 allow remote attackers to hijack the authentication of administrators for requests that (1) modify credentials via the role parameter to users/create/, …
- CVE-2011-5300MEDIUMCVSS v2 6.8EG 6.82015-01-01
Cross-site request forgery (CSRF) vulnerability in admin/setup/config/users.php in poMMo Aardvark PR16.1 allows remote attackers to hijack the authentication of administrators for requests that modify credentials via certain admin_ paramet…
- CVE-2011-5302MEDIUMCVSS v2 6.8EG 6.82015-01-01
Cross-site request forgery (CSRF) vulnerability in adm/admin_edit.php in PHPDug 2.0.0 allows remote attackers to hijack the authentication of administrators for requests that modify credentials.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →