Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2021-09-23 CVE-2021-22950 Cross-Site Request Forgery (CSRF) vulnerability in Concretecms Concrete CMS
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"
network
low complexity
concretecms CWE-352
6.5
2021-09-23 CVE-2021-22953 Cross-Site Request Forgery (CSRF) vulnerability in Concretecms Concrete CMS
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"
network
low complexity
concretecms CWE-352
5.4
2021-09-20 CVE-2021-24583 Cross-Site Request Forgery (CSRF) vulnerability in Motopress Timetable and Event Schedule
The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events.
network
low complexity
motopress CWE-352
4.3
2021-09-15 CVE-2020-21321 Cross-Site Request Forgery (CSRF) vulnerability in Emlog 6.0.0
emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.
network
low complexity
emlog CWE-352
4.3
2021-09-15 CVE-2021-40965 Cross-Site Request Forgery (CSRF) vulnerability in Tinyfilemanager Project Tinyfilemanager 2.4.6
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.
network
low complexity
tinyfilemanager-project CWE-352
8.8
2021-09-15 CVE-2020-21126 Cross-Site Request Forgery (CSRF) vulnerability in Metinfo 7.0.0
MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.
network
low complexity
metinfo CWE-352
8.8
2021-09-15 CVE-2020-19159 Cross-Site Request Forgery (CSRF) vulnerability in Laiketui 3.0
Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'.
network
low complexity
laiketui CWE-352
8.8
2021-09-14 CVE-2021-23026 Cross-Site Request Forgery (CSRF) vulnerability in F5 products
BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.
network
low complexity
f5 CWE-352
8.8
2021-09-14 CVE-2020-21081 Cross-Site Request Forgery (CSRF) vulnerability in Maccms 8.0
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.
network
low complexity
maccms CWE-352
6.5
2021-09-14 CVE-2021-39124 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Data Center and Jira
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request.
network
low complexity
atlassian CWE-352
4.3