Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-09-30 CVE-2015-9233 Cross-Site Request Forgery (CSRF) vulnerability in Codepeople CP Contact Form With Paypal
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
network
low complexity
codepeople CWE-352
8.8
2017-09-26 CVE-2017-13129 Cross-Site Request Forgery (CSRF) vulnerability in Zkteco Zktime web 2.0.1.12280
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.
network
low complexity
zkteco CWE-352
8.0
2017-09-26 CVE-2017-7969 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric Citect Anywhere and Powerscada Anywhere
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests.
network
low complexity
schneider-electric CWE-352
8.8
2017-09-25 CVE-2015-7293 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
network
low complexity
plone zope CWE-352
8.8
2017-09-25 CVE-2015-5182 Cross-Site Request Forgery (CSRF) vulnerability in Redhat AMQ
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
network
low complexity
redhat CWE-352
8.8
2017-09-25 CVE-2017-14683 Cross-Site Request Forgery (CSRF) vulnerability in Geminabox Project Geminabox
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
network
low complexity
geminabox-project CWE-352
8.8
2017-09-21 CVE-2015-0276 Cross-Site Request Forgery (CSRF) vulnerability in Kallithea-Scm Kallithea 0.1
Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2.
network
low complexity
kallithea-scm CWE-352
8.8
2017-09-21 CVE-2017-12253 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions.
network
low complexity
cisco CWE-352
8.8
2017-09-20 CVE-2015-5395 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
network
low complexity
debian alinto CWE-352
8.8
2017-09-20 CVE-2015-5607 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery in the REST API in IPython 2 and 3.
network
low complexity
ipython fedoraproject CWE-352
8.8