Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2020-01-28 CVE-2013-3093 Cross-Site Request Forgery (CSRF) vulnerability in Asus products
ASUS RT-N56U devices allow CSRF.
network
low complexity
asus CWE-352
8.8
2020-01-28 CVE-2015-5483 Cross-Site Request Forgery (CSRF) vulnerability in Private Only Project Private Only 3.5.1
Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or (4) conduct cross-site scripting (XSS) attacks via the po_logo parameter in the privateonly.php page to wp-admin/options-general.php.
network
low complexity
private-only-project CWE-352
8.8
2020-01-28 CVE-2013-4865 Cross-Site Request Forgery (CSRF) vulnerability in Micasaverde Veralite Firmware 1.5.408
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.
network
low complexity
micasaverde CWE-352
6.5
2020-01-26 CVE-2020-7991 Cross-Site Request Forgery (CSRF) vulnerability in Adive Framework 2.0.8
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
network
low complexity
adive CWE-352
8.8
2020-01-23 CVE-2014-2050 Cross-Site Request Forgery (CSRF) vulnerability in Owncloud
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
network
low complexity
owncloud CWE-352
6.5
2020-01-23 CVE-2019-16513 Cross-Site Request Forgery (CSRF) vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
network
low complexity
connectwise CWE-352
8.8
2020-01-23 CVE-2020-7210 Cross-Site Request Forgery (CSRF) vulnerability in Umbraco CMS 8.2.2
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
network
low complexity
umbraco CWE-352
4.3
2020-01-22 CVE-2011-3612 Cross-Site Request Forgery (CSRF) vulnerability in Usebb
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
network
low complexity
usebb CWE-352
8.8
2020-01-22 CVE-2011-3582 Cross-Site Request Forgery (CSRF) vulnerability in Anelectron Advanced Electron Forums 1.0.9
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
network
low complexity
anelectron CWE-352
8.8
2020-01-21 CVE-2020-6849 Cross-Site Request Forgery (CSRF) vulnerability in Hutchhouse Marketo Forms and Tracking 1.0.0/1.0.1/1.0.2
The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
network
low complexity
hutchhouse CWE-352
8.8