Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Zeppelin MEDIUM 6.1
CVE-2026-44613

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a…

Fix: 0.12.1+
Fix from $1,600 2026-07-30
Jspwiki HIGH 8.8
CVE-2026-28813

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Apisix CRITICAL 9.3
CVE-2026-49871

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manag…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apache Airflow Providers Keycloak MEDIUM 5.4
CVE-2026-40948

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login …

Fix: 0.7.0+
Fix from $1,600 2026-04-18
Geode HIGH 8.8
CVE-2025-47410

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricke…

Fix: 1.15.2+
Fix from $1,950 2025-10-18
Ofbiz HIGH 8.8
CVE-2024-48962

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a…

Fix: 18.12.17+
Fix from $1,950 2024-11-18
Cloudstack HIGH 8.8
CVE-2024-45693

Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of t…

Fix: 4.18.2.4 / 4.19.1.2+
Fix from $1,950 2024-10-16
Zeppelin MEDIUM 5.4
CVE-2021-28656

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue aff…

Fix: after 0.9.0
Fix from $1,600 2024-04-09
Wicket MEDIUM 6.5
CVE-2024-27439

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wick…

Fix: 9.17.0+
Fix from $1,600 2024-03-19
Airflow MEDIUM 6.5
CVE-2023-49920

Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. A…

Fix: after 2.7.3
Fix from $1,600 2023-12-21
Superset HIGH 8.8
CVE-2022-43719

Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio…

Fix: after 1.5.2
Fix from $1,950 2023-01-16
Jspwiki HIGH 8.8
CVE-2022-34158

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri…

Fix: 2.11.3+
Fix from $1,950 2022-08-04
Jspwiki MEDIUM 6.5
CVE-2022-28731EPSS 57%

A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacke…

Fix: 2.11.3+
Fix from $1,600 2022-08-04
Jspwiki HIGH 8.8
CVE-2022-24947

Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2…

Fix: 2.11.2+
Fix from $1,950 2022-02-25
Myfaces HIGH 7.5
CVE-2021-26296

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptograph…

Fix: after 2.3.7
Fix from $1,950 2021-02-19
Ofbiz HIGH 8.8
CVE-2019-0235EPSS 33%

Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

No fix yet
Fix from $1,950 2020-04-30
Airflow HIGH 8.8
CVE-2019-0229

A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site reques…

Fix: after 1.10.2
Fix from $1,950 2019-04-10
Airflow HIGH 8.8
CVE-2017-17835

In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.

Fix: after 1.8.2
Fix from $1,950 2019-01-23
Cxf Fediz HIGH 8.8
CVE-2017-12631

Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty…

Fix: 1.3.3+
Fix from $1,950 2017-11-30
Wicket HIGH 8.8
CVE-2016-6806

Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. …

Mitigation only
Fix from $1,950 2017-10-03
Brooklyn HIGH 8.8
CVE-2016-8737

In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to prod…

Fix: after 0.9.0
Fix from $1,950 2017-09-13
Openmeetings HIGH 8.8
CVE-2017-7666

Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.

Mitigation only
Fix from $1,950 2017-07-17
Archiva HIGH 8.0
CVE-2017-5657

Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the …

Fix: after 2.2.1
Fix from $1,950 2017-05-22
Cxf Fediz HIGH 8.8
CVE-2017-7661

Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty…

Fix: after 1.4.0
Fix from $1,950 2017-05-16
Cxf Fediz HIGH 8.8
CVE-2017-7662

Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows c…

Fix: after 1.3.2
Fix from $1,950 2017-05-16
Jackrabbit HIGH 8.8
CVE-2016-6801

Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x be…

Mitigation only
Fix from $1,950 2016-09-21
Archiva HIGH 8.8
CVE-2016-4469EPSS 8%

Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of…

Fix: after 1.3.9
Fix from $1,950 2016-07-28
Struts HIGH 8.8
CVE-2016-4430

Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac…

Mitigation only
Fix from $1,950 2016-07-04
Tomcat HIGH 8.8
CVE-2015-5351EPSS 10%

The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a…

No fix yet
Fix from $1,950 2016-02-25
Struts MEDIUM 6.8
CVE-2014-7809

Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha…

No fix yet
Fix from $1,600 2014-12-10