Vulnerability index

Browse CVEs

18 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Debian Linux HIGH 7.5
CVE-2024-34069

Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a de…

Fix: 3.0.3+
Fix from $1,950 2024-05-06
Debian Linux HIGH 8.8
CVE-2021-44227

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin passwo…

Fix: 2.1.38+
Fix from $1,950 2021-12-02
Debian Linux HIGH 8.0
CVE-2021-42097

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain …

Fix: 2.1.35+
Fix from $1,950 2021-10-21
Debian Linux MEDIUM 6.5
CVE-2020-12626

An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not consid…

Fix: 1.4.4+
Fix from $1,600 2020-05-04
Debian Linux MEDIUM 6.5
CVE-2012-4385

letodms 3.3.6 has CSRF via change password

No fix yet
Fix from $1,600 2019-11-13
Debian Linux MEDIUM 6.5
CVE-2013-6275

Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

Fix: after 5.1.2
Fix from $1,600 2019-11-05
Debian Linux HIGH 8.8
CVE-2013-6364

Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

No fix yet
Fix from $1,950 2019-11-05
Debian Linux MEDIUM 5.3
CVE-2013-6365

Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

Patch available
Fix from $1,600 2019-11-05
Debian Linux HIGH 8.8
CVE-2019-16993

In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Pa…

Fix: after 3.1.7
Fix from $1,950 2019-09-30
Debian Linux HIGH 8.8
CVE-2019-12466

Wikimedia MediaWiki through 1.32.1 allows CSRF.

Fix: after 1.32.1
Fix from $1,950 2019-07-10
Debian Linux HIGH 8.8
CVE-2017-0362

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.

Fix: 1.27.2 / 1.28.1+
Fix from $1,950 2018-04-13
Debian Linux HIGH 8.8
CVE-2018-8764

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for …

Fix: 6.3+
Fix from $1,950 2018-03-27
Debian Linux HIGH 8.8
CVE-2015-5395

Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.

Fix: 3.1.0+
Fix from $1,950 2017-09-20
Debian Linux HIGH 8.8
CVE-2017-7178

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitr…

Fix: 1.3.14+
Fix from $1,950 2017-03-18
Debian Linux MEDIUM 6.8
CVE-2015-7984

Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition …

Fix: 5.2.8 / 5.2.11+
Fix from $1,600 2015-11-19
Debian Linux MEDIUM 6.8
CVE-2014-5204

wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce ar…

Fix: after 3.9.1
Fix from $1,600 2014-08-18
Debian Linux MEDIUM 6.8
CVE-2014-2327

Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users fo…

Fix: after 0.8.8b
Fix from $1,600 2014-04-23
Debian Linux MEDIUM 6.8
CVE-2011-2522EPSS 10%

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attack…

Fix: 3.3.16 / 3.4.14+
Fix from $1,600 2011-07-29