CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-42621 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via /admin/admin_editor.php
CVSS 8.8
CVE-2024-42618 HIGH
Pligg CMS 2.0.2 - Cross-Site Request Forgery via /module.php?module=karma
CVSS 8.8
CVE-2024-42617 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via Admin Config Save
CVSS 8.8
CVE-2024-42616 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via Widget Removal Endpoint
CVSS 8.8
CVE-2024-42613 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via Widget Installation
CVSS 8.8
CVE-2024-42611 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via Admin Page Delete Parameter
CVSS 8.8
CVE-2024-42610 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via Backup Admin Endpoint
CVSS 8.8
CVE-2024-42609 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via Admin Backup Endpoint
CVSS 8.8
CVE-2024-42607 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via /admin/admin_backup.php
CVSS 8.8
CVE-2024-42606 HIGH
Pligg CMS 2.0.2 - Cross-Site Request Forgery via Admin Log Clear Parameter
CVSS 8.8
CVE-2024-42605 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via /admin/edit_page.php
CVSS 8.8
CVE-2024-42604 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via Admin Group Deletion
CVSS 8.8
CVE-2024-42603 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via Admin Backup Clearall Parameter
CVSS 8.8
CVE-2024-42608 HIGH
Pligg CMS v2.0.2 - Cross-Site Request Forgery via /admin/submit_page.php
CVSS 8.8
CVE-2024-42586 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42585 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42584 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42583 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42582 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42581 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42580 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42579 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42578 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.0
CVE-2024-42577 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
CVE-2024-42576 HIGH
Warehouse Inventory System v2.0 - CSRF
CVSS 8.8
Details
Vulnerabilities 9,347
Exploit Likelihood Medium