CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,348 vulnerabilities with CWE-352
CVE-2024-2125 HIGH
EnvíaloSimple: Email Marketing y Newsletters - CSRF
CVSS 8.8
CVE-2024-1315 HIGH
Classified Listing Plugin <= 3.0.4 - Cross-Site Request Forgery via rtcl_update_user_account
CVSS 8.8
CVE-2024-0588 MEDIUM
Paid Memberships Pro <2.12.10 - CSRF
CVSS 4.3
CVE-2024-31369 MEDIUM
PenciDesign Soledad < 8.4.2 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-27631 MEDIUM
GNU Savane < 3.13 - Cross-Site Request Forgery via siteadmin/usergroup.php
CVSS 6.0
CVE-2024-31205 MEDIUM
Saleor 3.10.0-3.14.63 - Cross-Site Request Forgery Bypass via Empty Refresh Token
CVSS 4.2
CVE-2024-22155 MEDIUM
WooCommerce < 8.5.2 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-2115 HIGH
LearnPress - WordPress LMS Plugin <4.0.0 - CSRF
CVSS 8.8
CVE-2024-27448 CRITICAL
maildev 2.0.0-beta1-2.1.0 - Remote Code Execution via Crafted Content-ID Header
CVSS 9.1
CVE-2024-30252 LOW
Livemarks < 3.7 - Cross-Site Request Forgery via subscribe.html
CVSS 2.6
CVE-2024-29192 HIGH
go2rtc < 1.8.5 - Cross-Site Request Forgery via /api/config Endpoint
CVSS 8.8
CVE-2024-25692 MEDIUM
Esri Portal for ArcGIS < 11.1 - Cross-Site Request Forgery via Crafted Form
CVSS 5.4
CVE-2024-20368 MEDIUM
Cisco Identity Services Engine 2.7.0-3.0.0 - Cross-Site Request Forgery
CVSS 6.5
CVE-2024-20347 MEDIUM
Cisco Emergency Responder - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-20281 HIGH
Cisco Nexus Dashboard and Hosted Services - Cross-Site Request Forgery
CVSS 7.5
CVE-2024-2322 MEDIUM
WooCommerce Cart Abandonment Recovery < 1.2.27 - Cross-Site Request Forgery in Bulk Actions
CVSS 6.8
CVE-2024-31109 HIGH
Toastie Studio Woocommerce Social Media Share Buttons <1.3.0 - CSRF
CVSS 7.1
CVE-2024-31105 HIGH
Adam Bowen Tax Rate Upload <2.4.5 - CSRF
CVSS 7.1
CVE-2024-3151 MEDIUM
Bdtask Multi-Store Inventory Management System <20240325 - CSRF
CVSS 4.3
CVE-2024-30965 HIGH
dedecms v5.7 - Cross-Site Request Forgery via member_scores.php
CVSS 8.8
CVE-2024-30946 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via /src/dede/co_do.php
CVSS 5.5
CVE-2024-1504 MEDIUM
SecuPress Free < 2.2.5.1 - Cross-Site Request Forgery via secupress_blackhole_ban_ip()
CVSS 4.3
CVE-2024-3147 MEDIUM
DedeCMS 5.7 - Cross-Site Request Forgery in makehtml_map.php
CVSS 4.3
CVE-2024-3146 MEDIUM
DedeCMS 5.7 - Cross-Site Request Forgery in makehtml_rss_action.php
CVSS 4.3
CVE-2024-3145 MEDIUM
DedeCMS 5.7 - Cross-Site Request Forgery in makehtml_js_action.php
CVSS 4.3
Details
Vulnerabilities 9,348
Exploit Likelihood Medium