CWE-352: Cross-Site Request Forgery (CSRF)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Yearly Trend
Top Affected Vendors
All Cross-Site Request Forgery (CSRF) CVEs (2,377)
This vulnerability allows attackers to bypass CSRF protection in NETGEAR JGS516PE and GS116Ev2 switches by omitting the CSRF token parameter in HTTP r...
Mar 10, 2021This CSRF vulnerability in Aruba AirWave Management Platform allows unauthenticated attackers to trick authenticated users into performing unauthorize...
Mar 5, 2021This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in e107 CMS versions through 2.3.0. The usersettings.php file lacks proper e_TOKE...
Mar 2, 2021This CSRF vulnerability in Jenkins Configuration Slicing Plugin allows attackers to trick authenticated users into unknowingly applying malicious slic...
Feb 24, 2021This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Open OnDemand, a web-based interface for high-performance computing clusters. ...
Feb 19, 2021This CSRF vulnerability in IBM Security Verify Information Queue allows attackers to trick authenticated users into performing unauthorized actions on...
Feb 11, 2021Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Tufin SecureTrack allow attackers to trick authenticated users into performing unintende...
Feb 9, 2021This Cross-Site Request Forgery (CSRF) vulnerability in JetBrains YouTrack allows attackers to trick authenticated users into uploading malicious atta...
Feb 3, 2021This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in EasyCMS v1.6 that allows attackers to create unauthorized admin accounts. Atta...
Feb 1, 2021This CSRF vulnerability in MediaWiki's Push extension allows attackers to perform unauthorized API actions by tricking authenticated users into visiti...
Jan 29, 2021This CSRF vulnerability in OpenEMR's GACL functionality allows attackers to trick authenticated users into performing unintended actions by sending sp...
Jan 28, 2021This CSRF vulnerability in Aterm WG2600HP and WG2600HP2 routers allows attackers to trick authenticated administrators into performing unintended acti...
Jan 28, 2021This vulnerability in CakePHP allows attackers to bypass CSRF protection by manipulating HTTP method override parameters. Attackers can submit arbitra...
Jan 26, 2021This CSRF vulnerability in Pepperl+Fuchs Comtrol IO-Link Master web interface allows attackers to trick authenticated users into performing unauthoriz...
Jan 22, 2021This CSRF vulnerability in Cisco DNA Center allows unauthenticated attackers to trick authenticated administrators into executing malicious actions vi...
Jan 20, 2021CVE-2020-35217 is a critical CSRF vulnerability in Vert.x-Web framework where CSRF verification incorrectly compares tokens within the session instead...
Jan 20, 2021This CSRF vulnerability in Anchor CMS allows attackers to trick authenticated administrators into unknowingly deleting admin user accounts. It affects...
Jan 19, 2021This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Bosch PRAESIDEO and PRAESENSA public address systems. Unauthenticated attacker...
Jan 14, 2021This CSRF vulnerability in IBM Curam Social Program Management allows attackers to trick authenticated users into performing unauthorized actions on t...
Jan 4, 2021CVE-2020-4917 is a Cross-Site Request Forgery (CSRF) vulnerability in IBM Cloud Pak System 2.3 that allows attackers to trick authenticated users into...
Jan 4, 2021CVE-2021-21495 is a Cross-Site Request Forgery (CSRF) vulnerability in MK-AUTH software that allows attackers to trick authenticated users into changi...
Jan 4, 2021CVE-2020-29458 is a Cross-Site Request Forgery (CSRF) vulnerability in Textpattern CMS 4.6.2 that allows attackers to trick authenticated administrato...
Dec 2, 2020This CSRF vulnerability in MCMS 4.6.5 allows attackers to create unauthorized administrator accounts by tricking authenticated users into visiting mal...
Sep 23, 2018This vulnerability in the Advanced Search WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against logged-in use...
Apr 15, 2024The TAX SERVICE Electronic HDM WordPress plugin before version 1.2.1 has an unauthenticated SQL injection vulnerability due to missing authorization a...
Nov 26, 2025This vulnerability allows attackers to bypass MediaProxy authentication in Concorde (formerly Nexkey) microblogging platforms, enabling unauthorized i...
Feb 11, 2025This CSRF vulnerability in JATOS v3.9.3 allows attackers to trick administrators into unknowingly resetting their passwords, leading to complete accou...
Nov 5, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Moodle's admin preset tool where actions lack anti-CSRF tokens. Attackers can ...
May 31, 2024A Cross-Site Request Forgery vulnerability in VirtueMart's product image upload function allows attackers to bypass CSRF protection tokens and upload ...
Jun 11, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the WP Video Posts WordPress plugin allows attackers to trick authenticated administrators into e...
Feb 24, 2025The WP Lead Plus X WordPress plugin has a Cross-Site Request Forgery vulnerability that allows unauthenticated attackers to trick administrators into ...
Oct 16, 2024This CSRF vulnerability allows remote attackers to trick authenticated administrators into performing unauthorized state-changing operations by visiti...
Jul 31, 2024This CSRF vulnerability in Ali2Woo Lite WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions, po...
Jun 21, 2024A CSRF vulnerability in Lollms WebUI versions up to 7.3.0 allows attackers to change victims' profile pictures without consent. This can lead to denia...
Jun 6, 2024CVE-2024-24820 is a Cross-Site Request Forgery (CSRF) vulnerability in Icinga Director that allows attackers to perform unauthorized configuration cha...
Feb 9, 2024This CSRF vulnerability in Argo CD allows attackers to execute API requests on behalf of authenticated users when they can inject HTML on the same par...
Jan 19, 2024This CSRF vulnerability allows remote unauthenticated attackers to trick authenticated administrators into executing malicious CLI commands via crafte...
Dec 13, 2023This vulnerability in SolarWinds Serv-U is a Cross-Site Request Forgery (CSRF) flaw where the server improperly validates CSRF tokens when requests co...
Dec 6, 2021This SQL injection vulnerability in SD.NET RIM allows attackers to execute arbitrary SQL commands through POST parameters 'idtyp' and 'idgremium' at t...
Feb 18, 2026A Cross-Site Request Forgery (CSRF) vulnerability in the josepsitjar StoryMap WordPress plugin allows attackers to trick authenticated administrators ...
Aug 14, 2025A Cross-Site Request Forgery vulnerability in the Webaholicson Epicwin WordPress plugin allows attackers to perform SQL injection attacks. This affect...
Jun 6, 2025This vulnerability in the occupancyplan WordPress plugin allows attackers to perform SQL injection via CSRF attacks. Attackers can trick authenticated...
May 23, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the Appointment Booking Calendar WordPress plugin allows attackers to trick authenticated adminis...
Apr 22, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the Eli EZ SQL Reports Shortcode Widget and DB Backup WordPress plugin allows attackers to trick ...
Mar 27, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the WP Google Review Slider WordPress plugin allows attackers to trick authenticated administrato...
Mar 27, 2025This CSRF vulnerability in Misskey's Bull dashboard allows attackers to perform unauthorized actions by tricking authenticated users into submitting m...
Feb 11, 2025CVE-2024-53829 is a cross-site request forgery (CSRF) vulnerability in CodeChecker that allows unauthenticated attackers to perform actions with the p...
Jan 21, 2025This vulnerability in the BSK Forms Blacklist WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Blin...
Jan 7, 2025This vulnerability in eDoc Intelligence LLC's eDoc Easy Tables WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks ...
Dec 2, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Post Ideas plugin that can lead to SQL injection. Attackers can ...
Nov 20, 2024About Cross-Site Request Forgery (CSRF) (CWE-352)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Our database tracks 2,377 CVEs classified as CWE-352, with 63 rated critical and 1,300 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.
External reference: View CWE-352 on MITRE CWE →
Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities
Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.
Start Monitoring Free