Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-04-29 CVE-2021-43937 Cross-Site Request Forgery (CSRF) vulnerability in Smartptt Scada Server 1.4
Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
network
low complexity
smartptt CWE-352
8.8
2022-04-29 CVE-2022-29903 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF for editing pages that store the extension's configuration.
network
low complexity
mediawiki CWE-352
4.3
2022-04-29 CVE-2022-29905 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:UserBoxes CSRF.
network
low complexity
mediawiki CWE-352
4.3
2022-04-28 CVE-2022-29555 Cross-Site Request Forgery (CSRF) vulnerability in Northern.Tech Mender
The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2.
network
low complexity
northern-tech CWE-352
8.8
2022-04-28 CVE-2022-28892 Cross-Site Request Forgery (CSRF) vulnerability in Mahara
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.
network
low complexity
mahara CWE-352
8.8
2022-04-28 CVE-2022-24879 Cross-Site Request Forgery (CSRF) vulnerability in Shopware
Shopware is an open source e-commerce software platform.
network
low complexity
shopware CWE-352
7.5
2022-04-25 CVE-2022-27374 Cross-Site Request Forgery (CSRF) vulnerability in Tenda Ax12 Firmware 22.03.01.21Cn
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.
network
low complexity
tenda CWE-352
6.5
2022-04-25 CVE-2022-27375 Cross-Site Request Forgery (CSRF) vulnerability in Tenda Ax12 Firmware 22.03.01.21Cn
Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.
network
low complexity
tenda CWE-352
6.5
2022-04-22 CVE-2022-27340 Cross-Site Request Forgery (CSRF) vulnerability in Mingsoft Mcms 5.2.7
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do.
network
low complexity
mingsoft CWE-352
8.8
2022-04-22 CVE-2021-38886 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm netapp CWE-352
8.8