CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,347 vulnerabilities with CWE-352
CVE-2024-28731
MEDIUM
DLink DWR-2000M Firmware 1.34ME - Cross-Site Request Forgery via Port Forwarding Option
CVSS 4.3
CVE-2024-11125
MEDIUM
GetSimpleCMS 3.3.16 - Cross-Site Request Forgery in Profile Management
CVSS 4.3
CVE-2024-51489
MEDIUM
Ampache - Cross-Site Request Forgery via Message Sending
CVSS 5.4
CVE-2024-51488
MEDIUM
Ampache - Cross-Site Request Forgery via Message Deletion
CVSS 5.4
CVE-2024-51487
HIGH
Ampache - Cross-Site Request Forgery in Catalog Activation/Deactivation
CVSS 8.1
CVE-2024-51485
HIGH
Ampache - Cross-Site Request Forgery in Plugin Activation/Deactivation
CVSS 8.1
CVE-2024-51484
HIGH
Ampache - Cross-Site Request Forgery in Controller Activation/Deactivation
CVSS 8.1
CVE-2024-51647
HIGH
Chaser324 Featured Posts Scroll - CSRF
CVSS 7.1
CVE-2024-51630
HIGH
Lars Schenk Responsive Flickr Gallery <2.3.1 - CSRF/XSS
CVSS 7.1
CVE-2024-52002
HIGH
Combodo iTop < 3.2.0 - Cross-Site Request Forgery
CVSS 8.8
CVE-2024-51157
MEDIUM
07flycms V1.3.9 - Cross-Site Request Forgery via OaSchedule Add Endpoint
CVSS 4.7
CVE-2024-50966
CRITICAL
dingfanzu CMS V1.0 - Cross-Site Request Forgery via Admin Action Endpoint
CVSS 9.3
CVE-2024-51382
HIGH
JATOS 3.9.3 - Cross-Site Request Forgery
CVSS 8.4
CVE-2024-51381
HIGH
JATOS 3.9.3 - Cross-Site Request Forgery
CVSS 8.4
CVE-2024-10711
HIGH
WooCommerce Report < 1.5.1 - Cross-Site Request Forgery via Settings Update Functionality
CVSS 8.8
CVE-2024-9689
MEDIUM
Post From Frontend < 1.0.0 - Cross-Site Request Forgery via Post Deletion
CVSS 4.3
CVE-2024-31998
HIGH
Combodo iTop - CSV Import Simulation CSRF
CVSS 8.8
CVE-2024-48057
MEDIUM
mudler/localai <=2.20.1 - Cross-Site Scripting via Delete Model API
CVSS 6.1
CVE-2024-30617
MEDIUM
Chamilo LMS 1.11.26 - Cross-Site Request Forgery in Social Wall Post
CVSS 5.4
CVE-2024-41744
MEDIUM
IBM CICS TX Standard 11.1 - Cross-Site Request Forgery
CVSS 6.5
CVE-2024-47359
MEDIUM
Depicter Slider <3.2.2 - Info Disclosure
CVSS 5.3
CVE-2024-39639
MEDIUM
WordPress File Upload < 4.24.7 - Cross-Site Request Forgery via Incorrectly Configured Access Control
CVSS 4.3
CVE-2024-10605
MEDIUM
Blood Bank Management System 1.0 - Cross-Site Request Forgery in /file/request.php
CVSS 4.3
CVE-2024-49685
MEDIUM
Smash Balloon Custom Twitter Feeds - CSRF
CVSS 5.4
CVE-2024-49674
CRITICAL
Lukas Huser EKC Tournament Manager - CSRF
CVSS 9.6
Details
Vulnerabilities
9,347
Exploit Likelihood
Medium