Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-04-18 CVE-2019-1722 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system.
network
low complexity
cisco CWE-352
6.5
2019-04-17 CVE-2019-10642 Cross-Site Request Forgery (CSRF) vulnerability in Contao CMS 4.7.0
Contao 4.7 allows CSRF.
network
low complexity
contao CWE-352
8.8
2019-04-17 CVE-2019-9176 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1.
network
low complexity
gitlab CWE-352
6.5
2019-04-17 CVE-2018-13810 Cross-Site Request Forgery (CSRF) vulnerability in Siemens CP 1604 Firmware and CP 1616 Firmware
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions).
network
low complexity
siemens CWE-352
6.5
2019-04-15 CVE-2018-16966 Cross-Site Request Forgery (CSRF) vulnerability in Filemanagerpro File Manager 3.0
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
network
low complexity
filemanagerpro CWE-352
8.8
2019-04-15 CVE-2018-17584 Cross-Site Request Forgery (CSRF) vulnerability in Wpfastestcache WP Fastest Cache 0.8.8.5
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
network
low complexity
wpfastestcache CWE-352
8.8
2019-04-15 CVE-2017-18366 Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.1.5
Subrion CMS 4.1.5 has CSRF in blog/delete/.
network
low complexity
intelliants CWE-352
8.8
2019-04-11 CVE-2019-11078 Cross-Site Request Forgery (CSRF) vulnerability in Mkcms Project Mkcms 5.0
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.
network
low complexity
mkcms-project CWE-352
8.8
2019-04-11 CVE-2019-11077 Cross-Site Request Forgery (CSRF) vulnerability in Fastadmin 1.0.0.20190111
FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI.
network
low complexity
fastadmin CWE-352
8.8
2019-04-10 CVE-2019-0229 Cross-Site Request Forgery (CSRF) vulnerability in Apache Airflow
A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site request forgery attacks.
network
low complexity
apache CWE-352
8.8