CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-31376 MEDIUM
Andrew Rapps Dashboard To-Do List <1.3.1 - CSRF
CVSS 4.3
CVE-2024-31374 MEDIUM
AppPresser <= 4.3.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31373 MEDIUM
E2Pdf e2pdf <= 1.20.27 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-30546 MEDIUM
Pixelite Login With Ajax <4.1 - CSRF
CVSS 4.3
CVE-2024-31940 MEDIUM
RedNao Extra Product Options Builder - CSRF
CVSS 4.3
CVE-2024-31938 MEDIUM
NewsXpress < 1.0.7 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31933 MEDIUM
Page Builder: Live Composer <= 1.5.35 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-31923 MEDIUM
PluginOps Feather Login Page <= 1.1.5 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31922 MEDIUM
Anton Aleksandrov WordPress Hosting Benchmark <1.3.6 - CSRF
CVSS 4.3
CVE-2024-31921 MEDIUM
Etoile Web Design Ultimate Product Catalogue <5.2.15 - CSRF
CVSS 4.3
CVE-2024-31920 MEDIUM
Tyche Softwares Currency per Product for WooCommerce - CSRF
CVSS 4.3
CVE-2024-31434 MEDIUM
Newsletter < 8.0.6 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-31433 MEDIUM
The Events Calendar <= 6.3.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31431 MEDIUM
Tyche Softwares Product Input Fields for WooCommerce <1.7.0 - CSRF
CVSS 4.3
CVE-2024-31429 MEDIUM
Blossom Themes Sarada Lite < 1.1.2 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31428 MEDIUM
The Conference < 1.2.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31427 MEDIUM
Marker.io < 1.1.8 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31426 MEDIUM
Data443 Inline Related Posts <3.3.1 - CSRF
CVSS 4.3
CVE-2024-31425 MEDIUM
TMS Amelia < 1.0.95 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-31424 HIGH
Hamid Alinia - idehweb <1.6.93 - CSRF
CVSS 8.8
CVE-2024-31422 MEDIUM
Philippe Bernard Favicon <1.3.29 - CSRF
CVSS 4.3
CVE-2024-22438 LOW
Hewlett Packard Enterprise OfficeConnect 1820 - RCE
CVSS 3.5
CVE-2024-32437 MEDIUM
impleCode eCommerce Product Catalog <3.3.28 - CSRF
CVSS 4.3
CVE-2024-32436 MEDIUM
Codemenschen Gift Vouchers <4.4.0 - CSRF
CVSS 4.3
CVE-2024-32435 MEDIUM
AffiEasy <= 1.1.4 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities 9,347
Exploit Likelihood Medium