Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-05-31 CVE-2016-10529 Cross-Site Request Forgery (CSRF) vulnerability in Droppy Project Droppy
Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests.
network
low complexity
droppy-project CWE-352
8.8
2018-05-30 CVE-2015-7610 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
network
low complexity
zimbra synacor CWE-352
8.8
2018-05-29 CVE-2018-11527 Cross-Site Request Forgery (CSRF) vulnerability in Cscms Project Cscms 4.1
An issue was discovered in CScms v4.1.
network
low complexity
cscms-project CWE-352
8.8
2018-05-26 CVE-2018-11500 Cross-Site Request Forgery (CSRF) vulnerability in Publiccms 4.0.20180210
An issue was discovered in PublicCMS V4.0.20180210.
network
low complexity
publiccms CWE-352
8.8
2018-05-26 CVE-2018-11493 Cross-Site Request Forgery (CSRF) vulnerability in Wuzhicms Wuzhi CMS 4.1.0
An issue was discovered in WUZHI CMS 4.1.0.
network
low complexity
wuzhicms CWE-352
8.8
2018-05-25 CVE-2017-9641 Cross-Site Request Forgery (CSRF) vulnerability in Osisoft PI Coresight
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system.
network
low complexity
osisoft CWE-352
8.8
2018-05-25 CVE-2018-11445 Cross-Site Request Forgery (CSRF) vulnerability in Easyservice Billing Project Easyservice Billing 1.0
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0.
network
low complexity
easyservice-billing-project CWE-352
8.8
2018-05-25 CVE-2018-11442 Cross-Site Request Forgery (CSRF) vulnerability in Easyservice Billing Project Easyservice Billing 1.0
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.
network
low complexity
easyservice-billing-project CWE-352
8.8
2018-05-24 CVE-2018-11405 Cross-Site Request Forgery (CSRF) vulnerability in Kliqqi CMS 2.0.2
Kliqqi 2.0.2 has CSRF in admin/admin_users.php.
network
low complexity
kliqqi CWE-352
8.8
2018-05-22 CVE-2018-11371 Cross-Site Request Forgery (CSRF) vulnerability in Skycaiji 1.2
SkyCaiji 1.2 allows CSRF to add an Administrator user.
network
low complexity
skycaiji CWE-352
8.8