Threats Tagged 'csrf'
View all threats tagged with 'csrf'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'csrf'
Click on any threat for detailed analysis and mitigation recommendations
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...] Join the discussion | Bleeping Computer | 09/25/2026, 18:13:33 UTC Added: 09/25/2026, 19:02:49 UTC |
Click2Shell is a cross-site request forgery (CSRF) vulnerability in WordPress Core up to version 7.1.0 that allows unauthenticated attackers to execute arbitrary PHP code on the server by forcing the installation of a theme from the official WordPress.org catalog. The attack requires a logged-in administrator to visit a crafted URL, which triggers the execution of PHP code via an inactive theme during a Customizer preview. This vulnerability was fixed in WordPress version 7.1.1 by escaping the theme slug and restricting jQuery selectors. The flaw enables remote code execution that could lead to file manipulation, data access, and creation of rogue admin accounts. Join the discussion | Bleeping Computer | 09/21/2026, 18:23:11 UTC Added: 09/21/2026, 18:31:40 UTC |
0 A Cross-Site Request Forgery (CSRF) vulnerability affects webpack_devserver version 5.2.5 and earlier. This vulnerability could allow unauthorized commands to be transmitted from a user that the web application trusts. Join the discussion | Exploit-DB RSS Feed | 08/17/2026, 00:00:00 UTC Added: 08/17/2026, 22:15:47 UTC |
A cross-site request forgery (CSRF) vulnerability exists in the Web Config interface embedded in multiple SEIKO EPSON printers and scanners. This vulnerability could allow an attacker to perform unauthorized actions on the device's web configuration interface if a user is tricked into submitting a crafted request. No specific affected versions or patch information is provided. Join the discussion | JVN Japan | 07/24/2026, 01:15:00 UTC Added: 08/04/2026, 13:25:04 UTC |
solaredge - (CSRF-OOB-Injection) Join the discussion | Exploit-DB RSS Feed | 05/21/2026, 00:00:00 UTC Added: 05/21/2026, 15:51:27 UTC |
RomM 4.4.0 - XSS_CSRF Chain Join the discussion | Exploit-DB RSS Feed | 04/09/2026, 00:00:00 UTC Added: 04/10/2026, 00:22:26 UTC |
XSS remains the top software weakness, followed by SQL injection and CSRF. Buffer overflow issues and improper access control make it to top 25. The post MITRE Releases 2025 List of Top 25 Most Dangerous Software Vulnerabilities appeared first on SecurityWeek . Join the discussion | SecurityWeek | 12/12/2025, 12:00:01 UTC Added: 12/12/2025, 12:05:36 UTC |
phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF) Join the discussion | Exploit-DB RSS Feed | 12/03/2025, 00:00:00 UTC Added: 12/03/2025, 17:58:37 UTC |
phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF) Join the discussion | Exploit-DB RSS Feed | 12/03/2025, 00:00:00 UTC Added: 12/03/2025, 17:58:37 UTC |
phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF) Join the discussion | Exploit-DB RSS Feed | 12/03/2025, 00:00:00 UTC Added: 12/03/2025, 16:58:17 UTC |
Showing 1 to 10 of 15 results