Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-02-15 CVE-2021-43941 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Data Center and Jira Server
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin.
network
low complexity
atlassian CWE-352
6.5
2022-02-15 CVE-2021-43953 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Data Center and Jira
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint.
network
low complexity
atlassian CWE-352
4.3
2022-02-15 CVE-2021-43952 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint.
network
low complexity
atlassian CWE-352
4.3
2022-02-11 CVE-2020-13674 Cross-Site Request Forgery (CSRF) vulnerability in Drupal
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues.
network
low complexity
drupal CWE-352
6.5
2022-02-09 CVE-2021-22954 Cross-Site Request Forgery (CSRF) vulnerability in Concretecms Concrete CMS
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.
network
low complexity
concretecms CWE-352
8.8
2022-02-08 CVE-2022-21703 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana netapp fedoraproject CWE-352
8.8
2022-02-08 CVE-2021-45326 Cross-Site Request Forgery (CSRF) vulnerability in Gitea
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.
network
low complexity
gitea CWE-352
8.8
2022-02-07 CVE-2021-24843 Cross-Site Request Forgery (CSRF) vulnerability in Supportcandy
The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action.
network
low complexity
supportcandy CWE-352
6.5
2022-02-07 CVE-2021-24879 Cross-Site Request Forgery (CSRF) vulnerability in Supportcandy
The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.
network
low complexity
supportcandy CWE-352
8.8
2022-02-07 CVE-2021-24993 Cross-Site Request Forgery (CSRF) vulnerability in Etoilewebdesign Ultimate Product Catalog
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example
network
low complexity
etoilewebdesign CWE-352
6.5