Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-09-02 CVE-2018-16365 Cross-Site Request Forgery (CSRF) vulnerability in Idreamsoft Icms 7.0.10
An issue was discovered in idreamsoft iCMS V7.0.10.
network
low complexity
idreamsoft CWE-352
8.8
2018-09-02 CVE-2018-16345 Cross-Site Request Forgery (CSRF) vulnerability in Easycms 1.5
An issue was discovered in EasyCMS 1.5.
network
low complexity
easycms CWE-352
8.8
2018-09-02 CVE-2018-16339 Cross-Site Request Forgery (CSRF) vulnerability in Phome Empirecms 7.0
An issue was discovered in EmpireCMS 7.0.
network
low complexity
phome CWE-352
8.8
2018-09-02 CVE-2018-16338 Cross-Site Request Forgery (CSRF) vulnerability in Auracms 2.3
An issue was discovered in AuraCMS 2.3.
network
low complexity
auracms CWE-352
8.8
2018-09-02 CVE-2018-16337 Cross-Site Request Forgery (CSRF) vulnerability in Chshcms Cscms 4.1.8
An issue was discovered in Cscms V4.1.8.
network
low complexity
chshcms CWE-352
6.5
2018-09-02 CVE-2018-16332 Cross-Site Request Forgery (CSRF) vulnerability in Idreamsoft Icms 7.0.9
An issue was discovered in iCMS 7.0.9.
network
low complexity
idreamsoft CWE-352
8.8
2018-09-02 CVE-2018-16331 Cross-Site Request Forgery (CSRF) vulnerability in Damicms 6.0.0
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
network
low complexity
damicms CWE-352
8.8
2018-09-01 CVE-2018-16315 Cross-Site Request Forgery (CSRF) vulnerability in Bijiadao Waimai Super CMS 20150505
In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.
network
low complexity
bijiadao CWE-352
6.5
2018-09-01 CVE-2018-16314 Cross-Site Request Forgery (CSRF) vulnerability in Icmsdev Icms 7.0.11
An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11.
network
low complexity
icmsdev CWE-352
8.8
2018-08-30 CVE-2018-11718 Cross-Site Request Forgery (CSRF) vulnerability in Xovis PC2 Firmware, Pc2R Firmware and PC3 Firmware
Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF.
network
low complexity
xovis CWE-352
8.8