Vulnerabilities (CVE)

Filtered by CWE-352
Total 5731 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5397 2 Oracle, Vmware 27 Application Testing Suite, Communications Brm - Elastic Charging Engine, Communications Diameter Signaling Router and 24 more 2022-07-25 2.6 LOW 5.3 MEDIUM
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.
CVE-2021-38868 1 Ibm 1 Engineering Requirements Quality Assistant On-premises 2022-07-25 N/A 6.5 MEDIUM
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.
CVE-2020-13673 1 Drupal 1 Entity Embed 2022-07-25 2.6 LOW 6.1 MEDIUM
The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.
CVE-2022-32289 1 Sygnoos 1 Popup Builder 2022-07-25 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.
CVE-2022-30337 1 Joomunited 1 Wp Meta Seo 2022-07-25 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin <= 4.4.8 at WordPress allows an attacker to update the social settings.
CVE-2022-1672 1 Insights From Google Pagespeed Project 1 Insights From Google Pagespeed 2022-07-18 6.8 MEDIUM 8.8 HIGH
The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
CVE-2022-2091 1 Cache Images Project 1 Cache Images 2022-07-18 4.3 MEDIUM 6.5 MEDIUM
The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any logged user upload images via a CSRF attack.
CVE-2022-2144 1 Jquery Validation For Contact Form 7 Project 1 Jquery Validation For Contact Form 7 2022-07-18 4.3 MEDIUM 4.3 MEDIUM
The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change Blog options like default_role, users_can_register via a CSRF attack
CVE-2020-35773 1 Freehtmldesigns 1 Site Offline 2022-07-17 6.8 MEDIUM 8.8 HIGH
The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
CVE-2022-2123 1 Wp Opt-in Project 1 Wp Opt-in 2022-07-15 4.3 MEDIUM 4.3 MEDIUM
The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used for sending spam emails.
CVE-2022-1957 1 Comment License Project 1 Comment License 2022-07-15 4.3 MEDIUM 4.3 MEDIUM
The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2022-1732 1 Rename Wp-login Project 1 Rename Wp-login 2022-07-15 4.3 MEDIUM 6.5 MEDIUM
The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2022-35228 1 Sap 1 Businessobjects Business Intelligence Platform 2022-07-15 6.8 MEDIUM 8.8 HIGH
SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would otherwise be restricted. This can be achieved only when a legitimate user accesses the application and a local compromise occurs, like sniffing or social engineering. On successful exploitation, the attacker can completely compromise the application.
CVE-2022-1626 1 Sharebar Project 1 Sharebar 2022-07-15 3.5 LOW 5.4 MEDIUM
The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them
CVE-2022-1576 1 Themeisle 1 Wp Maintenance Mode \& Coming Soon 2022-07-15 4.3 MEDIUM 6.5 MEDIUM
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
CVE-2022-1599 1 Admin Management Xtended Project 1 Admin Management Xtended 2022-07-15 4.3 MEDIUM 6.5 MEDIUM
The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowing attackers to make a logged users with the right capabilities to call them. This can lead to changes in post status (draft, published), slug, post date, comment status (enabled, disabled) and more.
CVE-2015-1785 1 Imagely 1 Nextgen Gallery 2022-07-14 4.3 MEDIUM 6.5 MEDIUM
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security measures preventing unwanted HTTP requests.
CVE-2021-31678 1 Pescms 1 Pescms Team 2022-07-14 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company.
CVE-2021-23163 1 Jfrog 1 Artifactory 2022-07-13 6.8 MEDIUM 8.8 HIGH
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific endpoints. This issue affects: JFrog JFrog Artifactory JFrog Artifactory versions before 7.33.6 versions prior to 7.x; JFrog Artifactory versions before 6.23.38 versions prior to 6.x.
CVE-2022-1967 1 Wp-championship Project 1 Wp-championship 2022-07-12 4.3 MEDIUM 6.5 MEDIUM
The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a logged in admin perform unwanted actions, such as create and delete arbitrary teams as well as update the plugin's settings. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues