Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2021-10-18 CVE-2021-24752 Cross-Site Request Forgery (CSRF) vulnerability in Catchplugins products
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu WordPress plugin before 1.7, Catch Scroll Progress Bar WordPress plugin before 1.6, Social Gallery and Widget WordPress plugin before 2.3, Catch Infinite Scroll WordPress plugin before 1.9, Catch Import Export WordPress plugin before 1.9, Catch Gallery WordPress plugin before 1.7, Catch Duplicate Switcher WordPress plugin before 1.6, Catch Breadcrumb WordPress plugin before 1.7, Catch IDs WordPress plugin before 2.4's configurations.
network
low complexity
catchplugins CWE-352
5.7
2021-10-14 CVE-2021-42228 Cross-Site Request Forgery (CSRF) vulnerability in Kindsoft Kindeditor
A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.
network
low complexity
kindsoft CWE-352
8.8
2021-10-14 CVE-2020-19964 Cross-Site Request Forgery (CSRF) vulnerability in PHPmywind 5.6
A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.
network
low complexity
phpmywind CWE-352
6.5
2021-10-13 CVE-2021-20126 Cross-Site Request Forgery (CSRF) vulnerability in Draytek Vigorconnect 1.6.0
Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
network
low complexity
draytek CWE-352
8.8
2021-10-13 CVE-2021-20795 Cross-Site Request Forgery (CSRF) vulnerability in Cybozu Remote Service Manager 3.1.8/3.1.9
Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.
network
low complexity
cybozu CWE-352
8.8
2021-10-13 CVE-2021-20831 Cross-Site Request Forgery (CSRF) vulnerability in OG Tags Project OG Tags
Cross-site request forgery (CSRF) vulnerability in OG Tags versions prior to 2.0.2 allows a remote attacker to hijack the authentication of administrators and unintended operation may be performed via unspecified vectors.
network
low complexity
og-tags-project CWE-352
8.8
2021-10-08 CVE-2021-41916 Cross-Site Request Forgery (CSRF) vulnerability in Webtareas Project Webtareas
A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile.
network
low complexity
webtareas-project CWE-352
8.8
2021-10-07 CVE-2021-20489 Cross-Site Request Forgery (CSRF) vulnerability in IBM Sterling File Gateway
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2021-10-06 CVE-2020-21658 Cross-Site Request Forgery (CSRF) vulnerability in Wdja CMS 1.5.2
A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a crafted URL.
network
low complexity
wdja CWE-352
6.5
2021-10-06 CVE-2021-29837 Cross-Site Request Forgery (CSRF) vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8