CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-7645 MEDIUM
Clinics Patient Management System 1.0 - Cross-Site Request Forgery in User Page
CVSS 4.3
CVE-2024-7574 MEDIUM
Christmasify! <= 1.5.5 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 6.1
CVE-2024-6136 MEDIUM
WordPress Plugin <8.5.6 - CSRF
CVSS 5.4
CVE-2024-40488 HIGH
Kashipara Live Membership System v1.0 - CSRF
CVSS 8.8
CVE-2024-40476 HIGH
SourceCodester Best House Rental Management System v1.0 - CSRF
CVSS 8.0
CVE-2024-7492 HIGH
MainWP Child Reports <= 2.2 - Cross-Site Request Forgery via network_options_action()
CVSS 8.8
CVE-2024-6720 HIGH
Light Poll WordPress Plugin < 1.0.0 - Cross-Site Request Forgery
CVSS 8.8
CVE-2024-41811 LOW
ipl/web < 0.10.1 - Cross-Site Request Forgery
CVSS 3.9
CVE-2024-5081 MEDIUM
wp-eMember < 10.7.0 - Cross-Site Request Forgery and Stored Cross-Site Scripting
CVSS 6.1
CVE-2024-2232 HIGH
2code/himer < 2.1.3 - Cross-Site Request Forgery via Group Invitation
CVSS 8.1
CVE-2024-7460 MEDIUM
OSWAPP Warehouse Inventory System 1.0/2.0 - Cross-Site Request Forgery in /change_password.php
CVSS 4.3
CVE-2024-7459 MEDIUM
OSWAPP Warehouse Inventory System 1.0/2.0 - Cross-Site Request Forgery in /edit_account.php
CVSS 4.3
CVE-2024-38776 HIGH
WP GoToWebinar < 15.7 - Cross-Site Request Forgery to Cross-Site Scripting
CVSS 7.1
CVE-2024-3238 HIGH
WordPress Menu Plugin <5.0.29 - XSS
CVSS 8.8
CVE-2024-7367 MEDIUM
Simple Realtime Quiz System 1.0 - Cross-Site Request Forgery via /ajax.php?action=save_user
CVSS 4.3
CVE-2024-32863 MEDIUM
exacqVision Web Service < 24.03 - Cross-Site Request Forgery
CVSS 6.8
CVE-2024-7360 MEDIUM
Tracking Monitoring Management System 1.0 - Cross-Site Request Forgery via /ajax.php
CVSS 4.3
CVE-2024-6040 HIGH
lollms_web_ui v9.8 - Cross-Site Request Forgery via Missing client_id Parameter
CVSS 8.8
CVE-2024-6496 MEDIUM
Light Poll < 1.0.0 - Cross-Site Request Forgery via Poll Deletion
CVSS 6.5
CVE-2024-3983 HIGH
WooCommerce Customers Manager <30.1 - CSRF
CVSS 8.1
CVE-2024-2843 MEDIUM
WooCommerce Customers Manager < 30.1 - Cross-Site Request Forgery via User Deletion
CVSS 6.5
CVE-2024-1747 MEDIUM
WooCommerce Customers Manager < 30.2 - CSRF & Stored XSS via AJAX Actions
CVSS 6.5
CVE-2024-40883 HIGH
ELECOM Wireless LAN Routers - Cross-Site Request Forgery
CVSS 8.8
CVE-2024-3083 HIGH
Proges Sensor Net Connect Firmware V2 - Cross-Site Request Forgery
CVSS 8.3
CVE-2024-6412 MEDIUM
HTML Forms < 1.3.34 - Cross-Site Request Forgery
CVSS 6.5
Details
Vulnerabilities 9,347
Exploit Likelihood Medium