CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-42557 HIGH
Hotel Management System <commit 91caab8 - CSRF
CVSS 8.8
CVE-2024-42555 HIGH
Hotel Management System <commit 91caab8 - CSRF
CVSS 8.8
CVE-2024-42553 HIGH
Hotel Management System <commit 91caab8 - CSRF
CVSS 8.8
CVE-2024-7850 MEDIUM
BP Profile Search <= 5.7.5 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 6.1
CVE-2024-7501 MEDIUM
Download Plugins and Themes in ZIP from Dashboard <= 1.8.7 - Cross-Site Request Forgery via download_theme() Function
CVSS 4.2
CVE-2024-7422 MEDIUM
Theme My Login <= 7.1.7 - Cross-Site Request Forgery via tml_admin_save_ms_settings()
CVSS 4.3
CVE-2024-42476 MEDIUM
CORDEA oauth < 0.11 - Cross-Site Request Forgery via State Parameter Bypass
CVSS 6.5
CVE-2024-42475 MEDIUM
CORDEA oauth < 0.11 - Insufficient Entropy in OAuth State Parameter
CVSS 6.5
CVE-2024-7420 MEDIUM
Insert PHP Code Snippet <= 1.3.6 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 5.8
CVE-2024-39410 MEDIUM
Adobe Commerce < 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-39409 MEDIUM
Adobe Commerce < 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-39408 MEDIUM
Adobe Commerce 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-38724 HIGH
Contact Form 7 Summary and Print <1.2.5 - XSS
CVSS 7.1
CVE-2024-42627 HIGH
FrogCMS v0.9.5 - Cross-Site Request Forgery via Snippet Delete Endpoint
CVSS 8.8
CVE-2024-42626 HIGH
FrogCMS v0.9.5 - Cross-Site Request Forgery via Snippet Add Endpoint
CVSS 8.8
CVE-2024-42625 HIGH
FrogCMS v0.9.5 - Cross-Site Request Forgery via /admin/?/layout/add
CVSS 8.8
CVE-2024-42624 HIGH
FrogCMS v0.9.5 - Cross-Site Request Forgery via Page Delete Endpoint
CVSS 8.8
CVE-2024-42623 HIGH
FrogCMS 0.9.5 - Cross-Site Request Forgery via Layout Delete Endpoint
CVSS 8.8
CVE-2024-42632 HIGH
FrogCMS 0.9.5 - Cross-Site Request Forgery via /admin/?/page/add
CVSS 8.8
CVE-2024-42631 HIGH
FrogCMS 0.9.5 - Cross-Site Request Forgery via Layout Edit Endpoint
CVSS 8.8
CVE-2024-42630 HIGH
FrogCMS v0.9.5 - Cross-Site Request Forgery via File Manager Create File Endpoint
CVSS 8.8
CVE-2024-42629 HIGH
FrogCMS 0.9.5 - Cross-Site Request Forgery via Page Edit Endpoint
CVSS 8.8
CVE-2024-42628 HIGH
FrogCMS v0.9.5 - Cross-Site Request Forgery via Snippet Edit Endpoint
CVSS 8.8
CVE-2024-7662 MEDIUM
Car Driving School Management System 1.0 - Cross-Site Request Forgery in Package Management
CVSS 4.3
CVE-2024-7661 MEDIUM
Car Driving School Management System 1.0 - Cross-Site Request Forgery in User Save Function
CVSS 4.3
Details
Vulnerabilities 9,347
Exploit Likelihood Medium