CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,364
Total CVEs
63
Critical
1,287
High
6.7
Avg CVSS

Yearly Trend

2026
121
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 52
2 Idccms 25
3 Ibm 23
4 Dedecms 14
5 Jfinalcms Project 10
6 Cisco 10
7 Flycms Project 9
8 Enalean 8
9 Tipsandtricks Hq 8
10 Pligg 8

All Cross-Site Request Forgery (CSRF) CVEs (2,364)

CVE-2025-23922
10.0

A Cross-Site Request Forgery (CSRF) vulnerability in the Harsh iSpring Embedder WordPress plugin allows attackers to trick authenticated administrator...

Jan 16, 2025
CVE-2025-48340
9.8

A Cross-Site Request Forgery (CSRF) vulnerability in the Danny Vink User Profile Meta Manager WordPress plugin allows attackers to trick authenticated...

May 19, 2025
CVE-2025-2907
9.8

This vulnerability in the Order Delivery Date WordPress plugin allows unauthenticated attackers to modify critical WordPress settings, including regis...

Apr 26, 2025
CVE-2025-31033
9.8

A Cross-Site Request Forgery (CSRF) vulnerability in the Adam Nowak Buddypress Humanity WordPress plugin allows attackers to trick authenticated users...

Apr 9, 2025
CVE-2025-23797
9.8

A Cross-Site Request Forgery vulnerability in the WP Options Editor WordPress plugin allows attackers to trick authenticated administrators into perfo...

Jan 16, 2025
CVE-2024-56012
9.8

This CSRF vulnerability in Pearlbells WordPress plugins allows attackers to trick authenticated users into performing unintended actions, potentially ...

Dec 16, 2024
CVE-2024-34502
9.8

This vulnerability allows unauthenticated attackers to merge lexemes in WikibaseLexeme without proper authorization. It affects MediaWiki installation...

May 5, 2024
CVE-2024-33449
9.8

This SSRF vulnerability in PDFMyURL allows attackers to make the service send requests to internal systems, potentially accessing sensitive data or ex...

Apr 29, 2024
CVE-2024-29684
9.8

DedeCMS v5.7 contains a CSRF vulnerability in the makehtml_homepage.php component that allows attackers to trick authenticated administrators into exe...

Mar 26, 2024
CVE-2023-4659
9.8

This CVE describes a critical Cross-Site Request Forgery vulnerability in Free5GC where attackers can bypass authentication by manipulating tokens or ...

Oct 2, 2023
CVE-2022-1574
9.8

The HTML2WP WordPress plugin through version 1.0.0 allows unauthenticated attackers to upload arbitrary files (including PHP files) to the server due ...

Jun 27, 2022
CVE-2022-1020
9.8

This vulnerability in the Product Table for WooCommerce WordPress plugin allows unauthenticated attackers to execute arbitrary PHP functions on affect...

Apr 18, 2022
CVE-2021-32122
9.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in certain NETGEAR WiFi extenders. Attackers can trick authenticated users into p...

Aug 11, 2021
CVE-2020-23426
9.8

CVE-2020-23426 is a privilege escalation vulnerability in zzcms 201910 that allows attackers to gain unauthorized administrative access through the /u...

Apr 8, 2021
CVE-2020-35950
9.8

This vulnerability in the XCloner Backup and Restore WordPress plugin allows Cross-Site Request Forgery (CSRF) attacks via almost any endpoint. Attack...

Jan 1, 2021
CVE-2025-52835
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the ConoHa by GMO WING WordPress Migrator plugin allows attackers to trick authenticated administ...

Dec 30, 2025
CVE-2025-11022
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows attackers to trick authenticated users into executing unintended ...

Dec 9, 2025
CVE-2024-45538
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in Synology's WebAPI Framework allows remote attackers to trick authenticated users into executing a...

Dec 4, 2025
CVE-2025-60156
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the AR For WordPress plugin allows attackers to trick authenticated administrators into unknowing...

Sep 26, 2025
CVE-2025-58255
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Custom Post Type Images plugin allows attackers to trick authenticated administrato...

Sep 22, 2025
CVE-2025-58997
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the Frenify Mow WordPress theme allows attackers to trick authenticated administrators into perfo...

Sep 9, 2025
CVE-2025-49381
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress ads.txt Guru Connect plugin allows attackers to trick authenticated administrators ...

Aug 20, 2025
CVE-2025-54010
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the Shahjahan Jewel FluentSnippets WordPress plugin allows attackers to trick authenticated admin...

Jul 16, 2025
CVE-2025-53095
9.6

Sunshine's web UI lacks CSRF protection, allowing attackers to trick authenticated users into executing arbitrary OS commands with Administrator privi...

Jul 1, 2025
CVE-2025-53314
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the WP Optimizer WordPress plugin allows attackers to trick authenticated administrators into per...

Jun 27, 2025
CVE-2025-39601
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the WPFactory Custom CSS, JS & PHP WordPress plugin allows attackers to trick authenticated admin...

Apr 16, 2025
CVE-2025-30967
9.6

A Cross-Site Request Forgery vulnerability in WPJobBoard WordPress plugin allows attackers to trick authenticated administrators into executing malici...

Apr 15, 2025
CVE-2025-32641
9.6

A Cross-Site Request Forgery vulnerability in Anant Addons for Elementor WordPress plugin allows attackers to trick authenticated administrators into ...

Apr 9, 2025
CVE-2025-32576
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the WP shop WordPress plugin allows attackers to trick authenticated administrators into uploadin...

Apr 9, 2025
CVE-2025-32496
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the Ultra Demo Importer WordPress plugin allows attackers to trick authenticated administrators i...

Apr 9, 2025
CVE-2025-30615
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the WP e-Commerce Style Email WordPress plugin allows attackers to inject malicious code when adm...

Mar 24, 2025
CVE-2024-7760
9.6

Aim version 3.22.0 has overly permissive CORS settings that allow cross-origin requests from any domain, enabling CSRF attacks on all tracking server ...

Mar 20, 2025
CVE-2025-25379
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in 07FLYCMS v1.3.9 allows remote attackers to trick authenticated users into executing unauthorized ...

Feb 28, 2025
CVE-2025-25106
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the FancyWP Starter Templates WordPress plugin allows attackers to trick authenticated administra...

Feb 7, 2025
CVE-2025-25101
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the MetricThemes Munk Sites WordPress plugin allows attackers to trick authenticated administrato...

Feb 7, 2025
CVE-2024-54372
9.6

A Cross-Site Request Forgery (CSRF) vulnerability in the Sourov Amin Insertify WordPress plugin allows attackers to trick authenticated administrators...

Dec 16, 2024
CVE-2024-52401
9.6

This CSRF vulnerability in Hacklog DownloadManager WordPress plugin allows attackers to trick authenticated administrators into uploading malicious we...

Nov 19, 2024
CVE-2024-8980
9.6

This CSRF vulnerability in Liferay's Script Console allows attackers to execute arbitrary Groovy code on affected servers by tricking authenticated ad...

Oct 22, 2024
CVE-2024-7568
9.6

This CSRF vulnerability in the Favicon Generator WordPress plugin allows unauthenticated attackers to delete arbitrary files on the server by tricking...

Aug 24, 2024
CVE-2024-41603
9.6

Spina CMS v2.18.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the /admin/layout endpoint that allows attackers to trick authenticate...

Jul 19, 2024
CVE-2024-38293
9.6

ALCASAR versions before 3.6.1 contain a Cross-Site Request Forgery (CSRF) vulnerability in activity.php that allows remote code execution. Attackers c...

Jun 13, 2024
CVE-2024-33913
9.6

This CSRF vulnerability in the Xserver Migrator WordPress plugin allows attackers to trick authenticated administrators into uploading arbitrary files...

May 2, 2024
CVE-2024-30560
9.6

This CSRF vulnerability in the DX-Watermark WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions...

Apr 25, 2024
CVE-2024-31988
9.6

This vulnerability allows remote code execution in XWiki Platform when the realtime editor is installed. An attacker can craft a malicious URL or imag...

Apr 10, 2024
CVE-2024-20252
9.6

Multiple CSRF vulnerabilities in Cisco Expressway Series and TelePresence VCS allow unauthenticated remote attackers to trick authenticated users into...

Feb 7, 2024
CVE-2024-22416
9.6

This CSRF vulnerability in pyLoad allows unauthenticated attackers to make arbitrary API calls via malicious GET requests. It affects all pyLoad insta...

Jan 18, 2024
CVE-2023-52200
9.6

This vulnerability in the ARMember WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to PHP object inje...

Jan 8, 2024
CVE-2023-51545
9.6

This vulnerability in the WordPress Job Manager & Career plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to PHP...

Dec 29, 2023
CVE-2023-48292
9.6

This is a critical CSRF vulnerability in XWiki Admin Tools that allows attackers to execute arbitrary shell commands on the server by tricking adminis...

Nov 20, 2023
CVE-2023-5820
9.6

This CSRF vulnerability in the Thumbnail Slider With Lightbox WordPress plugin allows attackers to upload arbitrary files by tricking administrators i...

Oct 27, 2023

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,364 CVEs classified as CWE-352, with 63 rated critical and 1,287 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free