Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-02-18 CVE-2019-8910 Cross-Site Request Forgery (CSRF) vulnerability in Wtcms Project Wtcms 1.0
An issue was discovered in WTCMS 1.0.
6.8
2019-02-18 CVE-2019-8902 Cross-Site Request Forgery (CSRF) vulnerability in Idreamsoft Icms
An issue was discovered in idreamsoft iCMS through 7.0.14.
4.9
2019-02-15 CVE-2019-0267 Cross-Site Request Forgery (CSRF) vulnerability in SAP Manufacturing Integration and Intelligence 15.0/15.1/15.2
SAP Manufacturing Integration and Intelligence, versions 15.0, 15.1 and 15.2, (Illuminator Servlet) currently does not provide Anti-XSRF tokens.
network
sap CWE-352
6.8
2019-02-15 CVE-2019-8347 Cross-Site Request Forgery (CSRF) vulnerability in Beescms 4.0
BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI.
network
beescms CWE-352
6.8
2019-02-11 CVE-2019-7738 Cross-Site Request Forgery (CSRF) vulnerability in C.P.Sub Project C.P.Sub 5.1/5.2
C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
5.8
2019-02-11 CVE-2019-7737 Cross-Site Request Forgery (CSRF) vulnerability in Verydows 2.0
A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.
network
verydows CWE-352
6.8
2019-02-11 CVE-2019-7730 Cross-Site Request Forgery (CSRF) vulnerability in Mywebsql 3.7
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
network
mywebsql CWE-352
4.9
2019-02-11 CVE-2018-20780 Cross-Site Request Forgery (CSRF) vulnerability in Traq 3.7.1
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
network
traq CWE-352
6.8
2019-02-07 CVE-2019-7570 Cross-Site Request Forgery (CSRF) vulnerability in Pbootcms 1.3.6
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
network
pbootcms CWE-352
5.8
2019-02-07 CVE-2019-7569 Cross-Site Request Forgery (CSRF) vulnerability in Wdoyo Doyo 2.3
An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update).
network
wdoyo CWE-352
6.8