Vulnerabilities (CVE)

Filtered by CWE-352
Total 5841 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49377 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
CVE-2023-49379 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.
CVE-2023-49378 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.
CVE-2023-49396 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
CVE-2023-49395 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
CVE-2023-49383 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
CVE-2023-49382 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
CVE-2023-49381 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
CVE-2023-49380 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
CVE-2023-49448 1 Jfinalcms Project 1 Jfinalcms 2023-12-09 N/A 8.8 HIGH
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
CVE-2015-5351 3 Apache, Canonical, Debian 3 Tomcat, Ubuntu Linux, Debian Linux 2023-12-08 6.8 MEDIUM 8.8 HIGH
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.
CVE-2023-24048 1 Connectize 2 Ac21000 G6, Ac21000 G6 Firmware 2023-12-08 N/A 8.8 HIGH
Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm.
CVE-2023-5884 1 Back2nature 1 Word Balloon 2023-12-08 N/A 6.5 MEDIUM
The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.
CVE-2023-5990 1 Funnelforms 1 Funnelforms Free 2023-12-08 N/A 6.5 MEDIUM
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not have CSRF checks on some of its form actions such as deletion and duplication, which could allow attackers to make logged in admin perform such actions via CSRF attacks
CVE-2023-5979 1 Implecode 1 Ecommerce Product Catalog 2023-12-08 N/A 6.5 MEDIUM
The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products
CVE-2023-47870 1 Gvectors 1 Wpforo Forum 2023-12-06 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6.
CVE-2023-31230 1 Baidu-tongji-generator Project 1 Baidu-tongji-generator 2023-12-06 N/A 6.1 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from n/a through 1.0.2.
CVE-2023-39166 1 Tagdiv 1 Tagdiv Composer 2023-12-06 N/A 6.1 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from n/a before 4.4.
CVE-2023-48278 1 Nitinrathod 1 Wp Forms Puzzle Captcha 2023-12-06 N/A 6.1 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Stored XSS.This issue affects WP Forms Puzzle Captcha: from n/a through 4.1.
CVE-2023-47875 1 Perfmatters 1 Perfmatters 2023-12-06 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Perfmatters allows Cross Site Request Forgery.This issue affects Perfmatters: from n/a through 2.1.6.