Csrf Magic Project maintains a narrowly scoped CSRF-protection library designed to mitigate cross-site request forgery vulnerabilities in web applications. The observed vulnerability exposure is concentrated in the csrf_magic product itself and centers on weaknesses in CSRF token handling and validation logic, which directly reflect the product's core defensive function. Current counts and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Csrf Magic Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7464HIGH In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, be | Aug 8, 2018 | 8.8 | 28 | NO | NO |
CVE-2019-17590HIGH The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it allows one to tamper with the csrf token values. A remote atta | Nov 26, 2019 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Csrf Magic Project.
Media articles that mention a CVE ID that affects a product developed by Csrf Magic Project — matched by CVE ID, not by vendor name.