CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,350 vulnerabilities with CWE-352
CVE-2023-27632 MEDIUM
mmrs151 Daily Prayer Time <= 2023.03.08 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-27623 MEDIUM
Jens Trnell WP Page Numbers <= 0.5 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-27611 MEDIUM
Reusable Blocks Extended <= 0.9 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-27431 MEDIUM
ThemeHunk Big Store <= 1.9.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-27418 MEDIUM
Wow-Company Side Menu Lite < 4.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-27417 MEDIUM
Affiliate Super Assistent <= 1.5.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-29425 MEDIUM
ShiftController Employee Shift Scheduling <= 4.9.23 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-29238 MEDIUM
Whydonate - FREE Donate button - Crowdfunding - Fundraising <= 3.12.15 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-28987 MEDIUM
Wpmet Wp Ultimate Review <= 2.0.3 - CSRF
CVSS 4.3
CVE-2023-28930 MEDIUM
Robin Phillips Mobile Banner <1.5 - CSRF
CVSS 4.3
CVE-2023-28696 MEDIUM
Harish Chouhan, Themeist I Recommend This - CSRF
CVSS 4.3
CVE-2023-28694 MEDIUM
Wbcom Designs - BuddyPress Activity Social Share <3.5.0 - CSRF
CVSS 5.4
CVE-2023-28618 MEDIUM
Marios Alexandrou Enhanced Plugin Admin <1.16 - CSRF
CVSS 5.4
CVE-2023-28498 MEDIUM
MotoPress Hotel Booking Lite <4.6.0 - CSRF
CVSS 4.3
CVE-2023-28497 MEDIUM
Tribulant Slideshow Gallery LITE <1.7.6 - CSRF
CVSS 5.4
CVE-2023-28495 MEDIUM
MyThemeShop WP Shortcode <1.4.16 - CSRF
CVSS 4.3
CVE-2023-31078 MEDIUM
WP BrowserUpdate <= 4.4.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-31077 MEDIUM
ReCorp Export WP Page to Static HTML/CSS <= 2.1.9 - CSRF
CVSS 4.3
CVE-2023-30478 MEDIUM
Tribulant Newsletters <= 4.8.8 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-29440 MEDIUM
PressTigers Simple Job Board <= 2.10.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-29428 MEDIUM
Superb Social Media Share Buttons and Follow Buttons for WordPress <= 1.1.3 - Cross-Site Request Forgery
CVSS 5.3
CVE-2023-29426 MEDIUM
Spreadshop Plugin <= 1.6.5 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-32502 MEDIUM
Pro Mime Types < 1.0.7 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-32501 MEDIUM
VikBooking Hotel Booking Engine & PMS <= 1.6.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-32500 MEDIUM
WoodMart < 7.1.1 - Cross-Site Request Forgery
CVSS 5.4
Details
Vulnerabilities 9,350
Exploit Likelihood Medium