Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2026-44613 Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-28813 Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 CRITICAL 9.3 CVE-2026-49871 Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manag… Apisix 3.17.0+ Fix from $2,3002026-06-19 MEDIUM 5.4 CVE-2026-40948 The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login … Apache Airflow Providers Keycloak 0.7.0+ Fix from $1,6002026-04-18 HIGH 8.8 CVE-2025-47410 Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricke… Geode 1.15.2+ Fix from $1,9502025-10-18 HIGH 8.8 CVE-2024-48962 Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a… Ofbiz 18.12.17+ Fix from $1,9502024-11-18 HIGH 8.8 CVE-2024-45693 Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing validation of the origin of t… Cloudstack 4.18.2.4 / 4.19.1.2+ Fix from $1,9502024-10-16 MEDIUM 5.4 CVE-2021-28656 Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue aff… Zeppelin after 0.9.0 Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-27439 An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wick… Wicket 9.17.0+ Fix from $1,6002024-03-19 MEDIUM 6.5 CVE-2023-49920 Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. A… Airflow after 2.7.3 Fix from $1,6002023-12-21 HIGH 8.8 CVE-2022-43719 Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset versio… Superset after 1.5.2 Fix from $1,9502023-01-16 HIGH 8.8 CVE-2022-34158 A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri… Jspwiki 2.11.3+ Fix from $1,9502022-08-04 MEDIUM 6.5 CVE-2022-28731EPSS 57% A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacke… Jspwiki 2.11.3+ Fix from $1,6002022-08-04 HIGH 8.8 CVE-2022-24947 Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2… Jspwiki 2.11.2+ Fix from $1,9502022-02-25 HIGH 7.5 CVE-2021-26296 In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptograph… Myfaces after 2.3.7 Fix from $1,9502021-02-19 HIGH 8.8 CVE-2019-0235EPSS 33% Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. Ofbiz No fix yet Fix from $1,9502020-04-30 HIGH 8.8 CVE-2019-0229 A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site reques… Airflow after 1.10.2 Fix from $1,9502019-04-10 HIGH 8.8 CVE-2017-17835 In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow. Airflow after 1.8.2 Fix from $1,9502019-01-23 HIGH 8.8 CVE-2017-12631 Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty… Cxf Fediz 1.3.3+ Fix from $1,9502017-11-30 HIGH 8.8 CVE-2016-6806 Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. … Wicket Mitigation only Fix from $1,9502017-10-03 HIGH 8.8 CVE-2016-8737 In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to prod… Brooklyn after 0.9.0 Fix from $1,9502017-09-13 HIGH 8.8 CVE-2017-7666 Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks. Openmeetings Mitigation only Fix from $1,9502017-07-17 HIGH 8.0 CVE-2017-5657 Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the … Archiva after 2.2.1 Fix from $1,9502017-05-22 HIGH 8.8 CVE-2017-7661 Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) sty… Cxf Fediz after 1.4.0 Fix from $1,9502017-05-16 HIGH 8.8 CVE-2017-7662 Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows c… Cxf Fediz after 1.3.2 Fix from $1,9502017-05-16 HIGH 8.8 CVE-2016-6801 Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x be… Jackrabbit Mitigation only Fix from $1,9502016-09-21 HIGH 8.8 CVE-2016-4469EPSS 8% Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of… Archiva after 1.3.9 Fix from $1,9502016-07-28 HIGH 8.8 CVE-2016-4430 Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attac… Struts Mitigation only Fix from $1,9502016-07-04 HIGH 8.8 CVE-2015-5351EPSS 10% The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions a… Tomcat No fix yet Fix from $1,9502016-02-25 MEDIUM 6.8 CVE-2014-7809 Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mecha… Struts No fix yet Fix from $1,6002014-12-10