CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,348 vulnerabilities with CWE-352
CVE-2024-27194 HIGH
Fontific | Google Fonts <0.1.6 - CSRF
CVSS 7.1
CVE-2024-2483 MEDIUM
Surya2Developer Hostel Management Service 1.0 - CSRF
CVSS 4.3
CVE-2024-27265 MEDIUM
IBM Integration Bus for z/OS <10.1.0.3 - CSRF
CVSS 4.5
CVE-2024-28195 HIGH
your_spotify < 1.9.0 - Cross-Site Request Forgery in API and Login Flow
CVSS 8.1
CVE-2024-28682 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via sys_cache_up.php
CVSS 6.3
CVE-2024-28681 MEDIUM
DedeCMS v5.7 - Cross-Site Request Forgery via /dede/plus_edit.php
CVSS 6.1
CVE-2024-28678 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via /dede/article_description_main.php
CVSS 6.3
CVE-2024-28677 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via article_keywords_main.php
CVSS 6.1
CVE-2024-28673 HIGH
DedeCMS v5.7 - Cross-Site Request Forgery via /dede/mychannel_edit.php
CVSS 8.8
CVE-2024-28672 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via media_edit.php
CVSS 5.4
CVE-2024-28670 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via /dede/freelist_main.php
CVSS 6.1
CVE-2024-28669 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via /dede/freelist_edit.php
CVSS 5.4
CVE-2024-1642 MEDIUM
MainWP Dashboard < 4.6.0.1 - Cross-Site Request Forgery via Posting Bulk Function
CVSS 4.3
CVE-2024-1489 MEDIUM
SMS Alert Order Notifications < 3.6.9 - Cross-Site Request Forgery via processBulkAction Function
CVSS 4.3
CVE-2024-0830 MEDIUM
Comments Extra Fields For Post,PAGES And CPT <5.0 - CSRF
CVSS 4.3
CVE-2024-0827 MEDIUM
Play.ht <= 3.6.4 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 4.3
CVE-2024-0592 MEDIUM
WordPress Related Posts <2.2.1 - CSRF
CVSS 5.4
CVE-2024-28684 HIGH
DedeCMS v5.7 - Cross-Site Request Forgery via /dede/module_main.php
CVSS 8.8
CVE-2024-28675 HIGH
DedeCMS v5.7 - Cross-Site Request Forgery via diy_edit.php
CVSS 8.8
CVE-2024-28667 MEDIUM
DedeCMS v5.7 - Cross-Site Request Forgery via templets_one_edit.php
CVSS 6.1
CVE-2024-28666 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via /dede/media_add.php
CVSS 5.5
CVE-2024-28665 HIGH
dedecms v5.7 - Cross-Site Request Forgery via article_add.php
CVSS 8.8
CVE-2024-28432 HIGH
dedecms v5.7 - Cross-Site Request Forgery via article_edit.php
CVSS 8.8
CVE-2024-28431 HIGH
dedecms v5.7 - Cross-Site Request Forgery via /dede/catalog_del.php
CVSS 8.8
CVE-2024-28430 MEDIUM
dedecms v5.7 - Cross-Site Request Forgery via /dede/catalog_edit.php
CVSS 6.1
Details
Vulnerabilities 9,348
Exploit Likelihood Medium