CWE-352 · 9,466 records
Cross-site request forgery
Why does it happen?
State-changing requests rely on the session cookie the browser sends automatically; nothing verifies that the request came from the user’s own page.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
app.use(session({ cookie: { httpOnly: true } }));app.post("/account/address", updateAddress);Fixed
app.use(session({ cookie: { httpOnly: true, sameSite: "lax" } }));app.post("/account/address", csrfProtection, updateAddress);How to prevent it
- 01Add an anti-CSRF token to every state-changing request.
- 02Use the SameSite attribute on session cookies.
- 03Require re-authentication for critical actions.
CVEs in this class
9,469 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2016-6277Weaponized | NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before netgear · d6220 firmware · CWE-352 | High8.8 | KEV | 99.8% | Dec 14, 2016 |
75This week | CVE-2014-100005Weaponized | Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.dlink · dir-600 firmware · CWE-352 | High8.0 | KEV | 43.5% | Jan 13, 2015 |
74This week | CVE-2023-2533Weaponized | PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRFpapercut · papercut mf · CWE-352 | High8.8 | KEV | 29.2% | Jun 20, 2023 |
73This week | CVE-2020-10181Weaponized | goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (adminisumavision · enhanced multimedia router firmware · CWE-352 | Critical9.8 | KEV | 14.7% | Mar 11, 2020 |
72This week | CVE-2008-4128Weaponized | Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Servcisco · ios · CWE-352 | High8.1 | KEV | 33.9% | Sep 18, 2008 |
63This week | CVE-2022-41622Weaponized | iControl SOAP vulnerabilityf5 · big-iq centralized management · CWE-352 | High8.8 | — | 92.3% | Dec 7, 2022 |
57Plan | CVE-2018-7700Proof of concept | DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specifydedecms · dedecms · CWE-352 | High8.8 | — | 74.1% | Mar 27, 2018 |
54Plan | CVE-2014-0054No exploit | The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entspringsource · spring framework · CWE-352 | Medium6.8 | — | 91.4% | Apr 17, 2014 |
54Plan | CVE-2013-6429No exploit | The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entitpivotal software · spring framework · CWE-352 | Medium6.8 | — | 90.6% | Jan 26, 2014 |
51Plan | CVE-2019-16667Proof of concept | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.netgate · pfsense · CWE-352 | High8.8 | — | 54.5% | Sep 26, 2019 |
47Plan | CVE-2015-2295Proof of concept | Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remotenetgate · pfsense · CWE-352 | Medium6.8 | — | 65.7% | Apr 10, 2015 |
47Plan | CVE-2019-9787Proof of concept | WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default confwordpress · wordpress · CWE-352 | High8.8 | — | 38.7% | Mar 14, 2019 |
47Plan | CVE-2022-1020Proof of concept | Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Callcodeastrology · woo product table · CWE-352 | Critical9.8 | — | 25.9% | Apr 18, 2022 |
46Plan | CVE-2015-6973Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authenticigniterealtime · openfire · CWE-352 | Medium6.8 | — | 64.8% | Sep 16, 2015 |
45Plan | CVE-2022-27226Proof of concept | A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administirz · ru21 firmware · CWE-352 | High8.8 | — | 33.7% | Mar 19, 2022 |
45Plan | CVE-2019-0235Proof of concept | Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.apache · ofbiz · CWE-352 | High8.8 | — | 32.7% | Apr 30, 2020 |
45Plan | CVE-2017-1000479Weaponized | pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrarnetgate · pfsense · CWE-352 | High8.8 | — | 31.7% | Jan 3, 2018 |
43Plan | CVE-2022-28731No exploit | Apache JSPWiki CSRF in UserPreferences.jspapache · jspwiki · CWE-352 | Medium6.5 | — | 57.8% | Aug 4, 2022 |
43Plan | CVE-2013-3568Weaponized | Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for recisco · linksys wrt110 firmware · CWE-352 | High8.8 | — | 25.1% | Feb 6, 2020 |
43Plan | CVE-2022-1574Proof of concept | HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Uploadhtml2wp project · html2wp · CWE-352 | Critical9.8 | — | 12.2% | Jun 27, 2022 |
42Plan | CVE-2023-48292Proof of concept | XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacksxwiki · admin tools · CWE-352 | High8.8 | — | 22.9% | Nov 20, 2023 |
41Plan | CVE-2023-22457No exploit | org.xwiki.contrib:application-ckeditor-ui vulnerable to Remote Code Execution via Cross-Site Request Forgeryxwiki · ckeditor integration · CWE-352 | High8.8 | — | 18.7% | Jan 4, 2023 |
41Plan | CVE-2021-25032Proof of concept | PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromisepublishpress · capabilities · CWE-352 | Critical9.8 | — | 6.7% | Jan 10, 2022 |
41Plan | CVE-2017-16780Proof of concept | The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.mybb · mybb · CWE-352 | Critical9.8 | — | 5.8% | Nov 10, 2017 |
41Plan | CVE-2019-17495Proof of concept | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPOsmartbear · swagger ui · CWE-352 | Critical9.8 | — | 5.7% | Oct 10, 2019 |
- CVE-2016-627795Now
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before
HighCVSS 8.8KEVWeaponizedEPSS 100%netgear · d6220 firmwareDec 14, 2016
- CVE-2014-10000575This week
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.
HighCVSS 8.0KEVWeaponizedEPSS 43%dlink · dir-600 firmwareJan 13, 2015
- CVE-2023-253374This week
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
HighCVSS 8.8KEVWeaponizedEPSS 29%papercut · papercut mfJun 20, 2023
- CVE-2020-1018173This week
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (admini
CriticalCVSS 9.8KEVWeaponizedEPSS 15%sumavision · enhanced multimedia router firmwareMar 11, 2020
- CVE-2008-412872This week
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Serv
HighCVSS 8.1KEVWeaponizedEPSS 34%cisco · iosSep 18, 2008
- CVE-2022-4162263This week
iControl SOAP vulnerability
HighCVSS 8.8WeaponizedEPSS 92%f5 · big-iq centralized managementDec 7, 2022
- CVE-2018-770057Plan
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify
HighCVSS 8.8Proof of conceptEPSS 74%dedecms · dedecmsMar 27, 2018
- CVE-2014-005454Plan
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external ent
MediumCVSS 6.8No exploitEPSS 91%springsource · spring frameworkApr 17, 2014
- CVE-2013-642954Plan
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entit
MediumCVSS 6.8No exploitEPSS 91%pivotal software · spring frameworkJan 26, 2014
- CVE-2019-1666751Plan
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.
HighCVSS 8.8Proof of conceptEPSS 55%netgate · pfsenseSep 26, 2019
- CVE-2015-229547Plan
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote
MediumCVSS 6.8Proof of conceptEPSS 66%netgate · pfsenseApr 10, 2015
- CVE-2019-978747Plan
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default conf
HighCVSS 8.8Proof of conceptEPSS 39%wordpress · wordpressMar 14, 2019
- CVE-2022-102047Plan
Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call
CriticalCVSS 9.8Proof of conceptEPSS 26%codeastrology · woo product tableApr 18, 2022
- CVE-2015-697346Plan
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentic
MediumCVSS 6.8Proof of conceptEPSS 65%igniterealtime · openfireSep 16, 2015
- CVE-2022-2722645Plan
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administ
HighCVSS 8.8Proof of conceptEPSS 34%irz · ru21 firmwareMar 19, 2022
- CVE-2019-023545Plan
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
HighCVSS 8.8Proof of conceptEPSS 33%apache · ofbizApr 30, 2020
- CVE-2017-100047945Plan
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar
HighCVSS 8.8WeaponizedEPSS 32%netgate · pfsenseJan 3, 2018
- CVE-2022-2873143Plan
Apache JSPWiki CSRF in UserPreferences.jsp
MediumCVSS 6.5No exploitEPSS 58%apache · jspwikiAug 4, 2022
- CVE-2013-356843Plan
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for re
HighCVSS 8.8WeaponizedEPSS 25%cisco · linksys wrt110 firmwareFeb 6, 2020
- CVE-2022-157443Plan
HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8Proof of conceptEPSS 12%html2wp project · html2wpJun 27, 2022
- CVE-2023-4829242Plan
XWiki Admin Tools Application Run Shell Command allows CSRF RCE attacks
HighCVSS 8.8Proof of conceptEPSS 23%xwiki · admin toolsNov 20, 2023
- CVE-2023-2245741Plan
org.xwiki.contrib:application-ckeditor-ui vulnerable to Remote Code Execution via Cross-Site Request Forgery
HighCVSS 8.8No exploitEPSS 19%xwiki · ckeditor integrationJan 4, 2023
- CVE-2021-2503241Plan
PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
CriticalCVSS 9.8Proof of conceptEPSS 7%publishpress · capabilitiesJan 10, 2022
- CVE-2017-1678041Plan
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
CriticalCVSS 9.8Proof of conceptEPSS 6%mybb · mybbNov 10, 2017
- CVE-2019-1749541Plan
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO
CriticalCVSS 9.8Proof of conceptEPSS 6%smartbear · swagger uiOct 10, 2019