Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-04-17 CVE-2019-9176 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1.
network
gitlab CWE-352
5.8
2019-04-17 CVE-2018-13810 Cross-Site Request Forgery (CSRF) vulnerability in Siemens CP 1604 Firmware and CP 1616 Firmware
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions).
network
siemens CWE-352
4.3
2019-04-15 CVE-2018-16966 Cross-Site Request Forgery (CSRF) vulnerability in Webdesi9 File Manager 3.0
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
network
low complexity
webdesi9 CWE-352
8.8
2019-04-15 CVE-2018-17584 Cross-Site Request Forgery (CSRF) vulnerability in Wpfastestcache WP Fastest Cache 0.8.8.5
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
6.8
2019-04-15 CVE-2017-18366 Cross-Site Request Forgery (CSRF) vulnerability in Intelliants Subrion CMS 4.1.5
Subrion CMS 4.1.5 has CSRF in blog/delete/.
6.8
2019-04-11 CVE-2019-11078 Cross-Site Request Forgery (CSRF) vulnerability in Mkcms Project Mkcms 5.0
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.
6.8
2019-04-11 CVE-2019-11077 Cross-Site Request Forgery (CSRF) vulnerability in Fastadmin 1.0.0.20190111
FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI.
network
fastadmin CWE-352
6.8
2019-04-10 CVE-2019-0229 Cross-Site Request Forgery (CSRF) vulnerability in Apache Airflow
A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vulnerable to cross-site request forgery attacks.
network
low complexity
apache CWE-352
8.8
2019-04-08 CVE-2018-2000 Cross-Site Request Forgery (CSRF) vulnerability in IBM products
IBM Business Automation Workflow 18.0.0.0 and 18.0.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
ibm CWE-352
6.8
2019-04-05 CVE-2019-10888 Cross-Site Request Forgery (CSRF) vulnerability in Ukcms 1.1.10
A CSRF Issue that can add an admin user was discovered in UKcms v1.1.10 via admin.php/admin/role/add.html.
network
ukcms CWE-352
6.8