Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-08-05 CVE-2016-3098 Cross-Site Request Forgery (CSRF) vulnerability in Thoughtbot Administrate
Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code.
network
low complexity
thoughtbot CWE-352
5.4
2022-08-04 CVE-2022-28731 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
network
low complexity
apache CWE-352
6.5
2022-08-04 CVE-2022-34158 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account.
network
low complexity
apache CWE-352
8.8
2022-08-03 CVE-2022-34937 Cross-Site Request Forgery (CSRF) vulnerability in Yuba U5Cms 8.3.5
Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php.
network
low complexity
yuba CWE-352
8.8
2022-08-02 CVE-2022-36968 Cross-Site Request Forgery (CSRF) vulnerability in Progress Ipswitch WS FTP Server
In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to mitigate the risk of cross-site request forgery (CSRF) attacks.
network
low complexity
progress CWE-352
4.3
2022-08-01 CVE-2022-34161 Cross-Site Request Forgery (CSRF) vulnerability in IBM Cics TX 11.1
IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2022-08-01 CVE-2022-26309 Cross-Site Request Forgery (CSRF) vulnerability in Pandorafms Pandora FMS
Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator group.
network
low complexity
pandorafms CWE-352
8.8
2022-07-27 CVE-2022-36882 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins GIT
A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.
network
low complexity
jenkins CWE-352
8.8
2022-07-27 CVE-2022-36886 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins External Monitor JOB Type
A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external job.
network
low complexity
jenkins CWE-352
4.3
2022-07-27 CVE-2022-36887 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins JOB Configuration History
A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations.
network
low complexity
jenkins CWE-352
4.3