CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,376
Total CVEs
63
Critical
1,299
High
6.7
Avg CVSS

Yearly Trend

2026
121
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 52
2 Idccms 25
3 Ibm 23
4 Dedecms 14
5 Cisco 11
6 Jfinalcms Project 10
7 Flycms Project 9
8 Pligg 8
9 Enalean 8
10 Tipsandtricks Hq 8

All Cross-Site Request Forgery (CSRF) CVEs (2,376)

CVE-2022-23888
8.8

CVE-2022-23888 is a Cross-Site Request Forgery (CSRF) vulnerability in YzmCMS v6.3 that allows attackers to trick authenticated users into performing ...

Jan 28, 2022
CVE-2021-22725
8.8

This CSRF vulnerability in Schneider Electric EVlink charging stations allows attackers to perform unauthorized actions by tricking authenticated user...

Jan 28, 2022
CVE-2021-44122
8.8

SPIP 4.0.0 has a CSRF vulnerability in multiple PHP files that allows authenticated attackers to execute malicious actions without user consent. Attac...

Jan 26, 2022
CVE-2022-0335
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in Moodle allows attackers to trick authenticated users into unknowingly deleting badge alignment...

Jan 25, 2022
CVE-2021-24696
8.8

The Simple Download Monitor WordPress plugin before version 3.9.9 lacks proper nonce validation, enabling Cross-Site Request Forgery (CSRF) attacks. A...

Jan 24, 2022
CVE-2022-0215
8.8

This CSRF vulnerability in XootiX WordPress plugins allows attackers to trick authenticated administrators into unknowingly executing malicious action...

Jan 18, 2022
CVE-2022-0180
8.8

This CSRF vulnerability in Quiz And Survey Master WordPress plugin allows attackers to trick administrators into performing unintended actions by visi...

Jan 17, 2022
CVE-2022-0197
8.8

CVE-2022-0197 is a Cross-Site Request Forgery (CSRF) vulnerability in phoronix-test-suite that allows attackers to trick authenticated users into perf...

Jan 13, 2022
CVE-2021-25051
8.8

The Modal Window WordPress plugin before version 5.2.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows authenticated attackers ...

Jan 10, 2022
CVE-2021-25053
8.8

This vulnerability in the WP Coder WordPress plugin allows attackers to include arbitrary files with PHP extensions or via data:// and http:// protoco...

Jan 10, 2022
CVE-2021-46147
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in MediaWiki's MassEditRegex extension. It allows attackers to trick authenticate...

Jan 10, 2022
CVE-2021-34086
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Ultimaker 3D printer web APIs. Attackers can trick authenticated users into ex...

Jan 10, 2022
CVE-2021-20165
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Trendnet AC2600 TEW-827DRU routers. Attackers can trick authenticated users in...

Dec 30, 2021
CVE-2021-4168
8.8

CVE-2021-4168 is a Cross-Site Request Forgery (CSRF) vulnerability in showdoc, a documentation tool. It allows attackers to trick authenticated users ...

Dec 26, 2021
CVE-2021-4131
8.8

CVE-2021-4131 is a Cross-Site Request Forgery (CSRF) vulnerability in Live Helper Chat that allows attackers to trick authenticated users into perform...

Dec 18, 2021
CVE-2021-29756
8.8

This CSRF vulnerability in IBM Cognos Analytics allows attackers to trick authenticated users into performing unauthorized actions on the My Inbox pag...

Dec 3, 2021
CVE-2021-44227
8.8

CVE-2021-44227 is a Cross-Site Request Forgery (CSRF) vulnerability in GNU Mailman that allows authenticated list members or moderators to obtain CSRF...

Dec 2, 2021
CVE-2021-4017
8.8

CVE-2021-4017 is a Cross-Site Request Forgery (CSRF) vulnerability in showdoc, a documentation tool. It allows attackers to trick authenticated users ...

Dec 1, 2021
CVE-2021-20851
8.8

This CSRF vulnerability in the Browser and Operating System Finder WordPress plugin allows attackers to trick administrators into performing unintende...

Dec 1, 2021
CVE-2021-42364
8.8

This vulnerability in the Stetic WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks due to missing nonce validatio...

Nov 29, 2021
CVE-2021-20845
8.8

This CSRF vulnerability in Unlimited Sitemap Generator allows attackers to trick authenticated administrators into performing unintended actions by vi...

Nov 24, 2021
CVE-2021-43559
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Moodle's badge deletion functionality. Attackers can trick authenticated users...

Nov 22, 2021
CVE-2021-44036
8.8

Team Password Manager versions before 10.135.236 have a Cross-Site Request Forgery (CSRF) vulnerability during import operations. This allows attacker...

Nov 19, 2021
CVE-2021-39353
8.8

This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against WordPress sites using the Easy Registration Forms plu...

Nov 19, 2021
CVE-2021-36908
8.8

This CSRF vulnerability in WP Reset PRO plugin allows attackers to trick authenticated administrators into performing unintended actions, specifically...

Nov 18, 2021
CVE-2021-24804
8.8

This vulnerability in the Simple JWT Login WordPress plugin allows attackers to change plugin settings without proper authentication checks. Attackers...

Nov 17, 2021
CVE-2021-25965
8.8

Calibre-web versions 0.6.0 to 0.6.13 contain a CSRF vulnerability that allows attackers to create admin accounts with attacker-controlled credentials....

Nov 16, 2021
CVE-2021-41426
8.8

CVE-2021-41426 is a Cross-Site Request Forgery (CSRF) vulnerability in Beeline Smart Box 2.0.38 routers that allows attackers to trick authenticated u...

Nov 10, 2021
CVE-2021-24809
8.8

This CSRF vulnerability in the BP Better Messages WordPress plugin allows attackers to trick logged-in users into performing unwanted actions in chat ...

Nov 1, 2021
CVE-2021-3901
8.8

CVE-2021-3901 is a Cross-Site Request Forgery (CSRF) vulnerability in Firefly III personal finance software that allows attackers to trick authenticat...

Oct 27, 2021
CVE-2021-20120
8.8

This CVE describes a cross-site request forgery (CSRF) vulnerability in the Arris Surfboard SB8200 cable modem administration interface. Attackers can...

Oct 21, 2021
CVE-2021-3858
8.8

CVE-2021-3858 is a Cross-Site Request Forgery (CSRF) vulnerability in Snipe-IT that allows attackers to trick authenticated users into performing unin...

Oct 19, 2021
CVE-2021-42228
8.8

This CSRF vulnerability in KindEditor 4.1.x allows attackers to trick authenticated users into performing unintended file uploads via malicious reques...

Oct 14, 2021
CVE-2021-20795
8.8

This CSRF vulnerability in Cybozu Remote Service management screens allows attackers to trick authenticated administrators into performing unintended ...

Oct 13, 2021
CVE-2021-24711
8.8

This CSRF vulnerability in the Software License Manager WordPress plugin allows attackers to trick authenticated administrators into performing unauth...

Oct 11, 2021
CVE-2021-41916
8.8

A CSRF vulnerability in webTareas version 2.4 and earlier allows attackers to trick authenticated administrators into unknowingly creating new adminis...

Oct 8, 2021
CVE-2021-20489
8.8

IBM Sterling File Gateway versions 2.2.0.0 through 6.1.1.0 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to trick au...

Oct 7, 2021
CVE-2021-29837
8.8

This CSRF vulnerability in IBM Sterling B2B Integrator allows attackers to trick authenticated users into performing unauthorized actions by sending m...

Oct 6, 2021
CVE-2021-34636
8.8

This CSRF vulnerability in the Countdown and CountUp WordPress plugin allows attackers to trick authenticated administrators into executing malicious ...

Sep 28, 2021
CVE-2021-40108
8.8

This CSRF vulnerability in Concrete CMS allows attackers to trick authenticated users into unknowingly adding malicious calendar events. Attackers can...

Sep 27, 2021
CVE-2021-3819
8.8

CVE-2021-3819 is a Cross-Site Request Forgery (CSRF) vulnerability in firefly-iii personal finance software. It allows attackers to trick authenticate...

Sep 27, 2021
CVE-2020-19951
8.8

This CSRF vulnerability in YzmCMS v5.5 allows attackers to trick authenticated users into performing unintended actions by submitting malicious reques...

Sep 23, 2021
CVE-2021-40965
8.8

This CSRF vulnerability in TinyFileManager allows attackers to trick authenticated administrators into executing malicious requests, leading to arbitr...

Sep 15, 2021
CVE-2020-21126
8.8

This CSRF vulnerability in MetInfo 7.0.0 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting a mal...

Sep 15, 2021
CVE-2021-24491
8.8

The Fileviewer WordPress plugin through version 2.2 lacks CSRF protection for file upload and delete operations. This allows attackers to trick logged...

Sep 13, 2021
CVE-2020-19263
8.8

This CSRF vulnerability in MipCMS v5.0.1 allows attackers to trick authenticated users into performing unauthorized privilege escalation actions. By c...

Sep 9, 2021
CVE-2021-38705
8.8

CVE-2021-38705 is a Cross-Site Request Forgery vulnerability in ClinicCases 7.3.3 that allows attackers to trick authenticated users into performing u...

Sep 7, 2021
CVE-2020-19047
8.8

This CSRF vulnerability in iWebShop v5.3 allows attackers to trick authenticated administrators into executing arbitrary code via a malicious POST req...

Aug 31, 2021
CVE-2021-21679
8.8

This vulnerability in Jenkins Azure AD Plugin allows attackers to bypass Cross-Site Request Forgery (CSRF) protection by crafting malicious URLs. Atta...

Aug 31, 2021
CVE-2021-40172
8.8

This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against Zoho ManageEngine Log360 proxy settings. Attackers ca...

Aug 29, 2021

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,376 CVEs classified as CWE-352, with 63 rated critical and 1,299 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free