Vulnerabilities (CVE)

Filtered by CWE-352
Total 9207 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-43459 1 Captainform 1 Captainform 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Forms by CaptainForm – Form Builder for WordPress plugin <= 2.5.3 versions.
CVE-2022-43418 1 Jenkins 1 Katalon 2026-06-17 N/A 4.3 MEDIUM
A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2022-43408 1 Jenkins 1 Pipeline\ 2026-06-17 N/A 6.5 MEDIUM
Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.
CVE-2022-43407 1 Jenkins 1 Pipeline\ 2026-06-17 N/A 8.8 HIGH
Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, which is used for the URLs that process user interactions for the given 'input' step (proceed or abort) and is not correctly encoded, allowing attackers able to configure Pipelines to have Jenkins build URLs from 'input' step IDs that would bypass the CSRF protection of any target URL in Jenkins when the 'input' step is interacted with.
CVE-2022-43323 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 8.8 HIGH
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.
CVE-2022-43031 1 Dedecms 1 Dedecms 2026-06-17 N/A 8.8 HIGH
DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and modify Admin passwords.
CVE-2022-42880 1 Auto Upload Images Project 1 Auto Upload Images 2026-06-17 N/A 6.1 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cross-Site Scripting (XSS).
CVE-2022-42751 1 Auieo 1 Candidats 2026-06-17 N/A 8.8 HIGH
CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.
CVE-2022-42447 1 Hcltech 1 Hcl Compass 2026-06-17 N/A 9.6 CRITICAL
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
CVE-2022-42435 1 Ibm 1 Business Automation Workflow 2026-06-17 N/A 4.3 MEDIUM
IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 238054.
CVE-2022-42246 1 Duofoxtechnologies 1 Duofox Cms 2026-06-17 N/A 8.8 HIGH
Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.
CVE-2022-42199 1 Simple Exam Reviewer Management System Project 1 Simple Exam Reviewer Management System 2026-06-17 N/A 8.8 HIGH
Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.
CVE-2022-42087 1 Tenda 2 Ax1803, Ax1803 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
CVE-2022-42086 1 Tenda 2 Ax1803, Ax1803 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function TendaAteMode.
CVE-2022-42078 1 Tenda 2 Ac1206, Ac1206 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
CVE-2022-42077 1 Tenda 2 Ac1206, Ac1206 Firmware 2026-06-17 N/A 6.5 MEDIUM
Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
CVE-2022-42070 1 Oretnom23 1 Online Birth Certificate Management System 2026-06-17 N/A 8.8 HIGH
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-41996 1 Theme-fusion 1 Avada 2026-06-17 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin installation/activation.
CVE-2022-41990 1 Cardozatechnologies 1 Cardoza-3d-tag-cloud 2026-06-17 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.
CVE-2022-41987 1 Badgeos 1 Badgeos 2026-06-17 N/A 6.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in LearningTimes BadgeOS plugin <= 3.7.1.6 versions.