CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-39158 HIGH
idccms v1.35 - Cross-Site Request Forgery via /admin/userSys_deal.php?mudi=infoSet
CVSS 8.8
CVE-2024-39157 LOW
idccms v1.35 - Cross-Site Request Forgery via /admin/ipRecord_deal.php
CVSS 3.8
CVE-2024-39156 LOW
idccms v1.35 - Cross-Site Request Forgery via /admin/keyWord_deal.php?mudi=add
CVSS 3.8
CVE-2024-39155 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/ipRecord_deal.php
CVSS 6.8
CVE-2024-39154 HIGH
idccms v1.35 - Cross-Site Request Forgery via /admin/keyWord_deal.php
CVSS 8.8
CVE-2024-39153 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/info_deal.php
CVSS 4.7
CVE-2024-4758 HIGH
Muslim Prayer Time BD < 2.5 - Cross-Site Request Forgery via Settings Reset
CVSS 7.6
CVE-2024-4757 HIGH
Logo Manager For Enamad < 0.7 - Cross-Site Request Forgery and Stored Cross-Site Scripting
CVSS 8.1
CVE-2024-4839 LOW
lollms-webui 9.6-latest - Cross-Site Request Forgery in Servers Configurations
CVSS 3.3
CVE-2024-4499 MEDIUM
lollms 9.6 - Cross-Site Request Forgery via Lax CORS Policy
CVSS 6.3
CVE-2024-5596 MEDIUM
ARMember Premium < 6.7 - Cross-Site Request Forgery via Incorrect Nonce Validation
CVSS 6.3
CVE-2024-3593 HIGH
UberMenu < 3.8.3 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 7.2
CVE-2024-37230 MEDIUM
Rara Theme Book Landing Page <= 1.2.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-37227 MEDIUM
Tribulant Newsletters < 4.9.7 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-37212 HIGH
Ali2Woo Lite < 3.3.5 - Cross-Site Request Forgery
CVSS 8.3
CVE-2024-37198 MEDIUM
blazethemes Digital Newspaper <= 1.1.5 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-37118 MEDIUM
Uncanny Automator Pro < 5.3 - Cross-Site Request Forgery Leading to License Settings Reset
CVSS 5.4
CVE-2024-35772 MEDIUM
presscustomizr Hueman <= 3.7.24 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-35771 MEDIUM
Customizr < 4.4.21 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-35770 MEDIUM
Vimeography < 2.4.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-4969 MEDIUM
Widget Bundle < 2.0.0 - Cross-Site Request Forgery via Widget Logging
CVSS 4.3
CVE-2024-4475 MEDIUM
WP Logs Book < 1.0.1 - Cross-Site Request Forgery via Log Clearing
CVSS 4.3
CVE-2024-4474 MEDIUM
WP Logs Book < 1.0.1 - Cross-Site Request Forgery in Settings Update
CVSS 4.3
CVE-2024-4382 MEDIUM
Wielebenwir Commonsbooking < 0.9.4.18 - CSRF
CVSS 6.5
CVE-2024-5676 MEDIUM
Paradox IP150 Internet Module <1.40.00 - CSRF
CVSS 6.8
Details
Vulnerabilities 9,347
Exploit Likelihood Medium