CWE-352: Cross-Site Request Forgery (CSRF)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Yearly Trend
Top Affected Vendors
All Cross-Site Request Forgery (CSRF) CVEs (2,376)
CVE-2022-23888 is a Cross-Site Request Forgery (CSRF) vulnerability in YzmCMS v6.3 that allows attackers to trick authenticated users into performing ...
Jan 28, 2022This CSRF vulnerability in Schneider Electric EVlink charging stations allows attackers to perform unauthorized actions by tricking authenticated user...
Jan 28, 2022SPIP 4.0.0 has a CSRF vulnerability in multiple PHP files that allows authenticated attackers to execute malicious actions without user consent. Attac...
Jan 26, 2022This Cross-Site Request Forgery (CSRF) vulnerability in Moodle allows attackers to trick authenticated users into unknowingly deleting badge alignment...
Jan 25, 2022The Simple Download Monitor WordPress plugin before version 3.9.9 lacks proper nonce validation, enabling Cross-Site Request Forgery (CSRF) attacks. A...
Jan 24, 2022This CSRF vulnerability in XootiX WordPress plugins allows attackers to trick authenticated administrators into unknowingly executing malicious action...
Jan 18, 2022This CSRF vulnerability in Quiz And Survey Master WordPress plugin allows attackers to trick administrators into performing unintended actions by visi...
Jan 17, 2022CVE-2022-0197 is a Cross-Site Request Forgery (CSRF) vulnerability in phoronix-test-suite that allows attackers to trick authenticated users into perf...
Jan 13, 2022The Modal Window WordPress plugin before version 5.2.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows authenticated attackers ...
Jan 10, 2022This vulnerability in the WP Coder WordPress plugin allows attackers to include arbitrary files with PHP extensions or via data:// and http:// protoco...
Jan 10, 2022This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in MediaWiki's MassEditRegex extension. It allows attackers to trick authenticate...
Jan 10, 2022This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Ultimaker 3D printer web APIs. Attackers can trick authenticated users into ex...
Jan 10, 2022This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Trendnet AC2600 TEW-827DRU routers. Attackers can trick authenticated users in...
Dec 30, 2021CVE-2021-4168 is a Cross-Site Request Forgery (CSRF) vulnerability in showdoc, a documentation tool. It allows attackers to trick authenticated users ...
Dec 26, 2021CVE-2021-4131 is a Cross-Site Request Forgery (CSRF) vulnerability in Live Helper Chat that allows attackers to trick authenticated users into perform...
Dec 18, 2021This CSRF vulnerability in IBM Cognos Analytics allows attackers to trick authenticated users into performing unauthorized actions on the My Inbox pag...
Dec 3, 2021CVE-2021-44227 is a Cross-Site Request Forgery (CSRF) vulnerability in GNU Mailman that allows authenticated list members or moderators to obtain CSRF...
Dec 2, 2021CVE-2021-4017 is a Cross-Site Request Forgery (CSRF) vulnerability in showdoc, a documentation tool. It allows attackers to trick authenticated users ...
Dec 1, 2021This CSRF vulnerability in the Browser and Operating System Finder WordPress plugin allows attackers to trick administrators into performing unintende...
Dec 1, 2021This vulnerability in the Stetic WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks due to missing nonce validatio...
Nov 29, 2021This CSRF vulnerability in Unlimited Sitemap Generator allows attackers to trick authenticated administrators into performing unintended actions by vi...
Nov 24, 2021This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Moodle's badge deletion functionality. Attackers can trick authenticated users...
Nov 22, 2021Team Password Manager versions before 10.135.236 have a Cross-Site Request Forgery (CSRF) vulnerability during import operations. This allows attacker...
Nov 19, 2021This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against WordPress sites using the Easy Registration Forms plu...
Nov 19, 2021This CSRF vulnerability in WP Reset PRO plugin allows attackers to trick authenticated administrators into performing unintended actions, specifically...
Nov 18, 2021This vulnerability in the Simple JWT Login WordPress plugin allows attackers to change plugin settings without proper authentication checks. Attackers...
Nov 17, 2021Calibre-web versions 0.6.0 to 0.6.13 contain a CSRF vulnerability that allows attackers to create admin accounts with attacker-controlled credentials....
Nov 16, 2021CVE-2021-41426 is a Cross-Site Request Forgery (CSRF) vulnerability in Beeline Smart Box 2.0.38 routers that allows attackers to trick authenticated u...
Nov 10, 2021This CSRF vulnerability in the BP Better Messages WordPress plugin allows attackers to trick logged-in users into performing unwanted actions in chat ...
Nov 1, 2021CVE-2021-3901 is a Cross-Site Request Forgery (CSRF) vulnerability in Firefly III personal finance software that allows attackers to trick authenticat...
Oct 27, 2021This CVE describes a cross-site request forgery (CSRF) vulnerability in the Arris Surfboard SB8200 cable modem administration interface. Attackers can...
Oct 21, 2021CVE-2021-3858 is a Cross-Site Request Forgery (CSRF) vulnerability in Snipe-IT that allows attackers to trick authenticated users into performing unin...
Oct 19, 2021This CSRF vulnerability in KindEditor 4.1.x allows attackers to trick authenticated users into performing unintended file uploads via malicious reques...
Oct 14, 2021This CSRF vulnerability in Cybozu Remote Service management screens allows attackers to trick authenticated administrators into performing unintended ...
Oct 13, 2021This CSRF vulnerability in the Software License Manager WordPress plugin allows attackers to trick authenticated administrators into performing unauth...
Oct 11, 2021A CSRF vulnerability in webTareas version 2.4 and earlier allows attackers to trick authenticated administrators into unknowingly creating new adminis...
Oct 8, 2021IBM Sterling File Gateway versions 2.2.0.0 through 6.1.1.0 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to trick au...
Oct 7, 2021This CSRF vulnerability in IBM Sterling B2B Integrator allows attackers to trick authenticated users into performing unauthorized actions by sending m...
Oct 6, 2021This CSRF vulnerability in the Countdown and CountUp WordPress plugin allows attackers to trick authenticated administrators into executing malicious ...
Sep 28, 2021This CSRF vulnerability in Concrete CMS allows attackers to trick authenticated users into unknowingly adding malicious calendar events. Attackers can...
Sep 27, 2021CVE-2021-3819 is a Cross-Site Request Forgery (CSRF) vulnerability in firefly-iii personal finance software. It allows attackers to trick authenticate...
Sep 27, 2021This CSRF vulnerability in YzmCMS v5.5 allows attackers to trick authenticated users into performing unintended actions by submitting malicious reques...
Sep 23, 2021This CSRF vulnerability in TinyFileManager allows attackers to trick authenticated administrators into executing malicious requests, leading to arbitr...
Sep 15, 2021This CSRF vulnerability in MetInfo 7.0.0 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting a mal...
Sep 15, 2021The Fileviewer WordPress plugin through version 2.2 lacks CSRF protection for file upload and delete operations. This allows attackers to trick logged...
Sep 13, 2021This CSRF vulnerability in MipCMS v5.0.1 allows attackers to trick authenticated users into performing unauthorized privilege escalation actions. By c...
Sep 9, 2021CVE-2021-38705 is a Cross-Site Request Forgery vulnerability in ClinicCases 7.3.3 that allows attackers to trick authenticated users into performing u...
Sep 7, 2021This CSRF vulnerability in iWebShop v5.3 allows attackers to trick authenticated administrators into executing arbitrary code via a malicious POST req...
Aug 31, 2021This vulnerability in Jenkins Azure AD Plugin allows attackers to bypass Cross-Site Request Forgery (CSRF) protection by crafting malicious URLs. Atta...
Aug 31, 2021This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against Zoho ManageEngine Log360 proxy settings. Attackers ca...
Aug 29, 2021About Cross-Site Request Forgery (CSRF) (CWE-352)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Our database tracks 2,376 CVEs classified as CWE-352, with 63 rated critical and 1,299 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.
External reference: View CWE-352 on MITRE CWE →
Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities
Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.
Start Monitoring Free