CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-5185 HIGH
EmbedAI < b2ad64a8 - Cross-Site Request Forgery via Weak Session Management
CVSS 7.3
CVE-2024-4429 MEDIUM
OpenText iManager 3.2.6.0200 - CSRF
CVSS 5.4
CVE-2024-5428 MEDIUM
SourceCodester Simple Online Bidding System 1.0 - Cross-Site Request Forgery in HTTP POST Request Handler
CVSS 4.3
CVE-2024-4535 HIGH
KKProgressbar2 Free < 1.1.4.2 - Cross-Site Request Forgery
CVSS 8.8
CVE-2024-4534 MEDIUM
KKProgressbar2 Free < 1.1.4.2 - Cross-Site Request Forgery and Stored Cross-Site Scripting
CVSS 6.1
CVE-2024-4532 MEDIUM
Business Card WordPress plugin <= 1.0.0 - Cross-Site Request Forgery
CVSS 6.4
CVE-2024-4531 HIGH
Business Card WordPress Plugin <= 1.0.0 - Cross-Site Request Forgery
CVSS 7.1
CVE-2024-4530 MEDIUM
Business Card WordPress Plugin <= 1.0.0 - Cross-Site Request Forgery via Card Category Editing
CVSS 6.3
CVE-2024-4529 MEDIUM
Business Card WordPress Plugin <= 1.0.0 - Cross-Site Request Forgery via Card Category Deletion
CVSS 5.0
CVE-2024-36255 MEDIUM
Mattermost <9.5.3, 9.6.1, 8.1.12 - RCE
CVSS 5.7
CVE-2024-4409 MEDIUM
WP-ViperGB <= 1.6.1 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 4.3
CVE-2024-35561 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/ca_deal.php
CVSS 5.4
CVE-2024-35560 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/ca_deal.php
CVSS 4.3
CVE-2024-35559 HIGH
idccms v1.35 - Cross-Site Request Forgery via /admin/infoMove_deal.php
CVSS 8.8
CVE-2024-35558 HIGH
idccms v1.35 - Cross-Site Request Forgery via /admin/ca_deal.php
CVSS 8.8
CVE-2024-35557 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/vpsApi_deal.php
CVSS 5.5
CVE-2024-35556 HIGH
idccms v1.35 - Cross-Site Request Forgery via /admin/vpsSys_deal.php?mudi=infoSet
CVSS 8.8
CVE-2024-35555 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/share_switch.php
CVSS 6.3
CVE-2024-35554 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/infoWeb_deal.php
CVSS 5.4
CVE-2024-35553 HIGH
idccms v1.35 - Cross-Site Request Forgery via /admin/infoMove_deal.php
CVSS 8.3
CVE-2024-35552 HIGH
idccms v1.35 - Cross-Site Request Forgery via /admin/infoMove_deal.php
CVSS 8.8
CVE-2024-35551 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/infoWeb_deal.php?mudi=add
CVSS 4.3
CVE-2024-35550 MEDIUM
idccms v1.35 - Cross-Site Request Forgery via /admin/infoWeb_deal.php?mudi=rev
CVSS 6.3
CVE-2024-35475 MEDIUM
OpenKM < 6.3.12 - Cross-Site Request Forgery in DatabaseQuery Endpoint
CVSS 6.4
CVE-2024-1446 MEDIUM
NextScripts: Social Networks Auto-Poster <= 4.4.3 - Cross-Site Request Forgery via nxssnap-reposter Page
CVSS 5.4
Details
Vulnerabilities 9,347
Exploit Likelihood Medium