Vulnerabilities (CVE)

Filtered by CWE-352
Total 6068 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1780 1 Latex Project 1 Latex 2024-02-28 3.5 LOW 5.4 MEDIUM
The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack which could also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
CVE-2022-29903 1 Mediawiki 1 Mediawiki 2024-02-28 4.3 MEDIUM 4.3 MEDIUM
The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration. The attacker must trigger a POST request to Special:PrivateDomains.
CVE-2022-1781 1 Posttabs Project 1 Posttabs 2024-02-28 3.5 LOW 5.4 MEDIUM
The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
CVE-2022-28992 1 Phpgurukul 1 Online Banquet Booking System 2024-02-28 6.8 MEDIUM 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.
CVE-2017-20088 1 Bytesforall 1 Atahualpa 2024-02-28 4.3 MEDIUM 4.3 MEDIUM
A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
CVE-2022-29735 1 Deltacontrols 2 Entelitouch, Entelitouch Firmware 2024-02-28 6.8 MEDIUM 8.8 HIGH
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a crafted HTTP request.
CVE-2022-34792 1 Jenkins 1 Recipe 2024-02-28 6.0 MEDIUM 8.0 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.
CVE-2022-1627 1 Zatzlabs 1 My Private Site 2024-02-28 4.3 MEDIUM 4.3 MEDIUM
The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2022-1594 1 Hc Custom Wp-admin Url Project 1 Hc Custom Wp-admin Url 2024-02-28 4.3 MEDIUM 4.3 MEDIUM
The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, allowing them to change the login URL
CVE-2022-1407 1 Vikwp 1 Hotel Booking Engine \& Pms 2024-02-28 4.3 MEDIUM 6.5 MEDIUM
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via a CSRF attack
CVE-2022-1792 1 Quick Subscribe Project 1 Quick Subscribe 2024-02-28 3.5 LOW 5.4 MEDIUM
The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them
CVE-2022-30969 1 Jenkins 1 Autocomplete Parameter 2024-02-28 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code without sandbox protection if the victim is an administrator.
CVE-2022-29437 1 Nextcode 1 Image Slider By Nextcode 2024-02-28 6.8 MEDIUM 8.8 HIGH
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
CVE-2022-30931 1 Employee Leaves Management System Project 1 Employee Leaves Management System 2024-02-28 4.3 MEDIUM 6.5 MEDIUM
Employee Leaves Management System (ELMS) V 2.1 is vulnerable to Cross Site Request Forgery (CSRF) via /myprofile.php.
CVE-2022-34780 1 Jenkins 1 Xebialabs Xl Release 2024-02-28 4.3 MEDIUM 6.5 MEDIUM
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2021-36890 1 Supsystic 1 Social Share Buttons 2024-02-28 4.3 MEDIUM 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress.
CVE-2022-27850 1 Plugin-planet 1 Simple Ajax Chat 2024-02-28 4.3 MEDIUM 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.
CVE-2022-1020 1 Codeastrology 1 Woo Product Table 2024-02-28 7.5 HIGH 9.8 CRITICAL
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated attackers to call arbitrary functions with either none or one user controlled argument
CVE-2022-26173 1 Jforum 1 Jforum 2024-02-28 6.8 MEDIUM 8.8 HIGH
JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.
CVE-2022-1847 1 Rotating Posts Project 1 Rotating Posts 2024-02-28 4.3 MEDIUM 4.3 MEDIUM
The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack