CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-8520 MEDIUM
Ultimate Member < 2.8.7 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 5.3
CVE-2024-41987 HIGH
TEM Opera Plus FM Family Transmitter - CSRF
CVE-2024-42504 MEDIUM
HPE IceWall Agent products - Cross-Site Request Forgery in Login Flow
CVSS 4.3
CVE-2024-8458 HIGH
PLANET GS-4210-24P2S and GS-4210-24PL4C Firmware - Cross-Site Request Forgery
CVSS 8.8
CVE-2024-28948 HIGH
Advantech ADAM-5630 Firmware < 2.5.2 - Cross-Site Request Forgery
CVSS 8.0
CVE-2024-9282 MEDIUM
1234n minicms < 1.11 - Cross-Site Request Forgery via page-edit.php
CVSS 4.3
CVE-2024-9281 MEDIUM
MiniCMS < 1.11 - Cross-Site Request Forgery in post-edit.php
CVSS 4.3
CVE-2024-45987 MEDIUM
Projectworld Online Voting System 1.0 - Cross-Site Request Forgery via voter.php
CVSS 6.5
CVE-2024-45983 MEDIUM
kishan0725 Hospital Management System 6.3.5 - Cross-Site Request Forgery via Doctor Record Deletion
CVSS 6.3
CVE-2024-45372 MEDIUM
MZK-DP300N Firmware <= 1.04 - Cross-Site Request Forgery
CVSS 6.5
CVE-2024-47315 MEDIUM
GiveWP <= 3.15.1 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-47305 MEDIUM
Use Any Font <= 6.3.08 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-47082 MEDIUM
strawberry-graphql < 0.243.0 - Cross-Site Request Forgery via Multipart File Upload
CVSS 4.6
CVE-2024-20437 HIGH
Cisco IOS XE - Unauthenticated Cross-Site Request Forgery via Web-Based Management Interface
CVSS 8.1
CVE-2024-20414 MEDIUM
Cisco IOS XE - Unauthenticated Cross-Site Request Forgery via HTTP GET Method
CVSS 6.5
CVE-2024-46600 MEDIUM
dingfanzu CMS 1.0 - Cross-Site Request Forgery via /admin/doAdminAction.php
CVSS 4.7
CVE-2024-46485 MEDIUM
dingfanzu CMS 1.0 - Cross-Site Request Forgery via /admin/doAdminAction.php
CVSS 6.3
CVE-2024-7892 MEDIUM
adstxt Plugin WordPress < 1.0.0 - Cross-Site Request Forgery in Settings Update
CVSS 4.3
CVE-2024-8476 MEDIUM
Easy PayPal Events <= 1.2.1 - Cross-Site Request Forgery via wpeevent_plugin_buttons() Function
CVSS 4.3
CVE-2024-7386 MEDIUM
Premium Packages - Sell Digital Products Securely <= 5.9.1 - Cross-Site Request Forgery via addRefund() Function
CVSS 4.3
CVE-2024-8795 HIGH
BA Book Everything <= 1.6.20 - Cross-Site Request Forgery via my_account_update() Function
CVSS 8.8
CVE-2024-46394 HIGH
FrogCMS v0.9.5 - Cross-Site Request Forgery via User Add Endpoint
CVSS 8.8
CVE-2024-46086 HIGH
FrogCMS V0.9.5 - Cross-Site Request Forgery via File Manager Delete Endpoint
CVSS 8.8
CVE-2024-44064 HIGH
LikeBtn Like Button Rating <= 2.6.53 - Cross-Site Scripting
CVSS 7.1
CVE-2024-46362 HIGH
FrogCMS V0.9.5 - Cross-Site Request Forgery via /admin/?/plugin/file_manager/create_directory
CVSS 8.8
Details
Vulnerabilities 9,347
Exploit Likelihood Medium