Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-01-18 CVE-2022-0215 Cross-Site Request Forgery (CSRF) vulnerability in Xootix products
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site.
network
low complexity
xootix CWE-352
8.8
2022-01-17 CVE-2022-0180 Cross-Site Request Forgery (CSRF) vulnerability in Expresstech Quiz and Survey Master
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
network
low complexity
expresstech CWE-352
8.8
2022-01-12 CVE-2021-41597 Cross-Site Request Forgery (CSRF) vulnerability in Salesagility Suitecrm
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
network
low complexity
salesagility CWE-352
8.8
2022-01-12 CVE-2022-20612 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.
network
low complexity
jenkins oracle CWE-352
4.3
2022-01-12 CVE-2022-20613 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
network
low complexity
jenkins oracle CWE-352
4.3
2022-01-12 CVE-2022-20619 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
7.1
2022-01-12 CVE-2022-23111 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Publish Over SSH
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
network
low complexity
jenkins CWE-352
4.3
2022-01-12 CVE-2022-23115 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Batch Task
Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve logs, build or delete a batch task.
network
low complexity
jenkins CWE-352
5.4
2022-01-11 CVE-2021-37198 Cross-Site Request Forgery (CSRF) vulnerability in Siemens Comos
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used).
network
low complexity
siemens CWE-352
8.8
2022-01-10 CVE-2021-25051 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window
The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.
network
low complexity
wow-company CWE-352
8.8