CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,376
Total CVEs
63
Critical
1,299
High
6.7
Avg CVSS

Yearly Trend

2026
121
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 52
2 Idccms 25
3 Ibm 23
4 Dedecms 14
5 Cisco 11
6 Jfinalcms Project 10
7 Flycms Project 9
8 Pligg 8
9 Enalean 8
10 Tipsandtricks Hq 8

All Cross-Site Request Forgery (CSRF) CVEs (2,376)

CVE-2021-40174
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Zoho ManageEngine Log360 that allows attackers to disable logon security setti...

Aug 29, 2021
CVE-2021-28490
8.8

This vulnerability in OWASP CSRFGuard allows attackers to bypass Cross-Site Request Forgery (CSRF) protection by retrieving the CSRF cookie using only...

Aug 19, 2021
CVE-2021-34645
8.8

This CSRF vulnerability in the Shopping Cart & eCommerce Store WordPress plugin allows attackers to trick authenticated administrators into executing ...

Aug 19, 2021
CVE-2020-22403
8.8

This CSRF vulnerability in Express Cart v1.1.16 allows attackers to trick authenticated administrators into performing unauthorized actions like addin...

Aug 12, 2021
CVE-2021-37366
8.8

CVE-2021-37366 is a CSRF vulnerability in CTparental's admin panel that, when combined with XSS, allows attackers to trick administrators into disabli...

Aug 10, 2021
CVE-2020-18694
8.8

This CSRF vulnerability in IgnitedCMS v1.0 allows attackers to trick authenticated administrators into performing unauthorized actions via the profile...

Aug 6, 2021
CVE-2021-37381
8.8

Southsoft GMIS 5.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized access to private student information, including...

Aug 6, 2021
CVE-2021-34634
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Nifty Newsletters WordPress plugin allows attackers to trick authenticated administrators ...

Aug 5, 2021
CVE-2021-34628
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Admin Custom Login WordPress plugin allows attackers to trick authenticated administrators...

Aug 2, 2021
CVE-2021-34637
8.8

This vulnerability in the Post Index WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks, enabling them to inject m...

Aug 2, 2021
CVE-2021-29757
8.8

CVE-2021-29757 is a cross-site request forgery (CSRF) vulnerability in IBM QRadar User Behavior Analytics 4.1.1 that allows attackers to trick authent...

Aug 2, 2021
CVE-2020-22761
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 that allows attackers to trick authenticated administrators into...

Jul 30, 2021
CVE-2021-34619
8.8

This CSRF vulnerability in WooCommerce Stock Manager WordPress plugin allows attackers to trick authenticated administrators into uploading arbitrary ...

Jul 21, 2021
CVE-2021-20782
8.8

This CSRF vulnerability in Software License Manager WordPress plugin allows attackers to trick administrators into performing unintended actions by se...

Jul 14, 2021
CVE-2020-4938
8.8

This CVE describes a cross-site request forgery (CSRF) vulnerability in IBM MQ Appliance versions 9.1 and 9.2. It allows attackers to trick authentica...

Jul 12, 2021
CVE-2021-20779
8.8

This CSRF vulnerability in WordPress Email Template Designer - WP HTML Mail plugin allows attackers to trick administrators into performing unintended...

Jul 7, 2021
CVE-2021-20102
8.8

Machform versions before 16 are vulnerable to cross-site request forgery (CSRF) attacks due to missing CSRF tokens. This allows attackers to trick aut...

Jun 29, 2021
CVE-2020-18648
8.8

This CSRF vulnerability in JuQingCMS v1.0 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically cr...

Jun 22, 2021
CVE-2021-34244
8.8

This CSRF vulnerability in Ice Hrm 29.0.0.OS allows attackers to create new administrator accounts or change existing user passwords without authoriza...

Jun 22, 2021
CVE-2021-32424
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in TrendNet TW100-S4W1CA routers. An attacker can trick an authenticated user int...

Jun 17, 2021
CVE-2021-31659
8.8

This CSRF vulnerability in TP-Link managed switches allows attackers to trick administrators into clicking malicious links that can change switch pass...

Jun 10, 2021
CVE-2021-21665
8.8

This CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows attackers to trick authenticated users into connecting Jenkins to attacker-contro...

Jun 10, 2021
CVE-2021-29995
8.8

This CSRF vulnerability in CloverDX Server Console allows attackers to trick authenticated users into executing arbitrary actions, including script ex...

Jun 9, 2021
CVE-2020-18264
8.8

CVE-2020-18264 is a Cross-Site Request Forgery vulnerability in Simple-Log v1.6 that allows attackers to trick authenticated administrators into perfo...

Jun 7, 2021
CVE-2020-26641
8.8

This CSRF vulnerability in iCMS 7.0.16 allows attackers to trick authenticated users into executing malicious web scripts without their knowledge. Att...

May 28, 2021
CVE-2019-14836
8.8

CVE-2019-14836 is a Cross-Site Request Forgery (CSRF) vulnerability in the 3scale developer portal login mechanism. This allows attackers to trick aut...

May 26, 2021
CVE-2021-21549
8.8

CVE-2021-21549 is a Cross-Site Request Forgery (CSRF) vulnerability in Dell EMC XtremIO XMS management software. It allows attackers to trick authenti...

May 21, 2021
CVE-2021-25931
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in OpenNMS Horizon and Meridian that allows attackers to trick administrators int...

May 20, 2021
CVE-2020-18195
8.8

This CSRF vulnerability in Pluck CMS v4.7.9 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically ...

May 17, 2021
CVE-2020-18964
8.8

This CSRF vulnerability in ForestBlog allows attackers to trick authenticated administrators into performing unauthorized actions via the management i...

May 11, 2021
CVE-2021-32096
8.8

CVE-2021-32096 is a Cross-Site Request Forgery (CSRF) vulnerability in NSA Emissary's ConsoleAction component that allows attackers to inject arbitrar...

May 7, 2021
CVE-2020-23264
8.8

This CSRF vulnerability in Fork-CMS allows attackers to trick logged-in administrators into performing unintended actions by crafting malicious reques...

May 6, 2021
CVE-2021-24178
8.8

This CSRF vulnerability in the Business Directory Plugin for WordPress allows attackers to trick logged-in administrators into performing unauthorized...

May 6, 2021
CVE-2021-30224
8.8

This CSRF vulnerability in Rukovoditel v2.8.3 allows attackers to trick authenticated administrators into unknowingly creating new admin accounts with...

Apr 29, 2021
CVE-2020-21989
8.8

CVE-2020-21989 is a Cross-Site Request Forgery vulnerability in HomeAutomation 3.3.2 that allows attackers to trick authenticated users into performin...

Apr 27, 2021
CVE-2021-31584
8.8

CVE-2021-31584 is a Cross-Site Request Forgery (CSRF) vulnerability in Sipwise C5 NGCP's www_csc web interface that allows attackers to trick authenti...

Apr 23, 2021
CVE-2021-27181
8.8

This vulnerability in MDaemon email server allows attackers to perform Cross-Site Request Forgery (CSRF) attacks by fixing anti-CSRF tokens. It affect...

Apr 14, 2021
CVE-2021-31152
8.8

This CSRF vulnerability in Multilaser Router AC1200 firmware allows attackers to trick authenticated users into performing unauthorized actions like e...

Apr 14, 2021
CVE-2021-24218
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Facebook for WordPress plugin allows attackers to trick authenticated administrators into ...

Apr 12, 2021
CVE-2021-20687
8.8

This CSRF vulnerability in Kagemai 0.8.8 allows attackers to trick authenticated administrators into performing unintended actions by crafting malicio...

Apr 7, 2021
CVE-2021-30147
8.8

This CSRF vulnerability in DMA Softlab Radius Manager 4.4.0 allows attackers to trick authenticated administrators into performing unauthorized action...

Apr 7, 2021
CVE-2021-24159
8.8

This vulnerability in the Contact Form 7 Style WordPress plugin allows attackers to inject malicious JavaScript through the custom CSS feature due to ...

Apr 5, 2021
CVE-2021-24161
8.8

This vulnerability allows attackers to trick WordPress administrators into uploading malicious zip archives through the Responsive Menu plugin. Succes...

Apr 5, 2021
CVE-2021-25924
8.8

CVE-2021-25924 is a Cross-Site Request Forgery vulnerability in GoCD's backup configuration endpoint that allows attackers to trick authenticated user...

Apr 1, 2021
CVE-2021-21629
8.8

This CSRF vulnerability in Jenkins Build With Parameters Plugin allows attackers to trick authenticated users into unknowingly triggering builds with ...

Mar 30, 2021
CVE-2021-21633
8.8

This CSRF vulnerability in Jenkins OWASP Dependency-Track Plugin allows attackers to trick authenticated users into connecting to malicious URLs, pote...

Mar 30, 2021
CVE-2021-21638
8.8

This CSRF vulnerability in Jenkins Team Foundation Server Plugin allows attackers to trick authenticated users into unknowingly connecting Jenkins to ...

Mar 30, 2021
CVE-2021-21627
8.8

This CSRF vulnerability in Jenkins Libvirt Agents Plugin allows attackers to stop hypervisor domains (virtual machines) managed by Jenkins. Attackers ...

Mar 18, 2021
CVE-2020-29553
8.8

This CSRF vulnerability in Grav CMS Scheduler allows attackers to trick authenticated administrators into executing arbitrary system commands by visit...

Mar 15, 2021
CVE-2020-24983
8.8

This is a Cross-Site Request Forgery (CSRF) vulnerability in Quadbase EspressReports ES that allows unauthenticated attackers to trick administrators ...

Mar 11, 2021

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,376 CVEs classified as CWE-352, with 63 rated critical and 1,299 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free