CSRF に分類される脆弱性に紐づく CVE を、公開年で絞り込みます。一覧は新しい公開が上に来る並びで、CVSS / EPSS のリスク指標でもさらに絞り込めます。
直近の脆弱性公開や傾向を押さえ、セキュリティチームが高リスクな事象や悪用の可能性を素早く把握するためのビューです。
2017 年に公開され、CSRF に分類される CVE を表示しています。 CVE の一覧へ
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2017-17990 | Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action. | 8.8 | 0.51% | 2017-12-29 | 2026-06-16 |
| CVE-2017-17982 | PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php. | 6.8 | 0.40% | 2017-12-29 | 2026-06-16 |
| CVE-2014-0120 | Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated by running "shutdown -f." | 8.8 | 1.15% | 2017-12-29 | 2026-06-16 |
| CVE-2017-17960 | PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php. | 8.8 | 0.51% | 2017-12-28 | 2026-06-16 |
| CVE-2017-17939 | PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php. | 8.8 | 0.46% | 2017-12-28 | 2026-06-16 |
| CVE-2017-17936 | Vanguard Marketplace Digital Products PHP has CSRF via /search. | 8.8 | 0.46% | 2017-12-28 | 2026-06-16 |
| CVE-2017-17930 | PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel. | 8.8 | 0.51% | 2017-12-27 | 2026-06-16 |
| CVE-2017-17908 | PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general. | 8.8 | 0.46% | 2017-12-27 | 2026-06-16 |
| CVE-2017-17905 | PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php. | 8.8 | 0.51% | 2017-12-27 | 2026-06-16 |
| CVE-2017-17903 | FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel. | 8.8 | 0.46% | 2017-12-27 | 2026-06-16 |
| CVE-2017-17894 | Readymade Job Site Script has CSRF via the /job URI. | 8.8 | 0.51% | 2017-12-27 | 2026-06-16 |
| CVE-2017-17891 | Readymade Video Sharing Script has CSRF via user-profile-edit.php. | 8.8 | 0.51% | 2017-12-27 | 2026-06-16 |
| CVE-2017-17830 | Bus Booking Script has CSRF via admin/new_master.php. | 6.8 | 0.44% | 2017-12-21 | 2026-06-16 |
| CVE-2017-17827 | Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions. | 8.8 | 0.77% | 2017-12-20 | 2026-06-16 |
| CVE-2017-5263 | Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session tokens associated with any web application function, especially destructive ones. | 8.0 | 0.30% | 2017-12-20 | 2026-06-16 |
| CVE-2017-1746 | IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519. | 8.8 | 0.53% | 2017-12-20 | 2026-06-16 |
| CVE-2017-1631 | IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 133140. | 8.8 | 0.53% | 2017-12-20 | 2026-06-16 |
| CVE-2017-17774 | admin/configuration.php in Piwigo 2.9.2 has CSRF. | 8.8 | 0.58% | 2017-12-19 | 2026-06-16 |
| CVE-2017-14092 | The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain. | 8.8 | 0.89% | 2017-12-15 | 2026-06-16 |
| CVE-2017-5264 | Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack. | 8.8 | 2.75% | 2017-12-14 | 2026-06-16 |