Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-05-24 CVE-2016-10757 Cross-Site Request Forgery (CSRF) vulnerability in Readaxo 5.2.0
In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.
network
readaxo CWE-352
6.8
2019-05-24 CVE-2016-10756 Cross-Site Request Forgery (CSRF) vulnerability in Kliqqi CMS 3.0.0.5
Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.
network
kliqqi CWE-352
6.8
2019-05-24 CVE-2019-10847 Cross-Site Request Forgery (CSRF) vulnerability in Computrols Building Automation Software
Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
6.8
2019-05-24 CVE-2018-19613 Cross-Site Request Forgery (CSRF) vulnerability in Westermo Dr-250 Firmware, Dr-260 Firmware and Mr-260 Firmware
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
network
westermo CWE-352
4.3
2019-05-22 CVE-2018-7828 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric products
A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen.
6.8
2019-05-21 CVE-2019-12253 Cross-Site Request Forgery (CSRF) vulnerability in Mylittleforum MY Little Forum
my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.
5.8
2019-05-13 CVE-2018-16136 Cross-Site Request Forgery (CSRF) vulnerability in Ipbrick OS 6.3
An issue was discovered in the administrator interface in IPBRICK OS 6.3.
network
ipbrick CWE-352
6.8
2019-05-13 CVE-2018-14711 Cross-Site Request Forgery (CSRF) vulnerability in Asus Rt-Ac3200 Firmware 3.0.0.4.382.50010
Missing cross-site request forgery protection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to cause state-changing actions with specially crafted URLs.
network
asus CWE-352
4.3
2019-05-13 CVE-2019-11886 Cross-Site Request Forgery (CSRF) vulnerability in Yellowpencil Visual CSS Style Editor
The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.
6.8
2019-05-10 CVE-2018-1790 Cross-Site Request Forgery (CSRF) vulnerability in IBM Financial Transaction Manager 3.0.2.0/3.0.2.1
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8