CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,379
Total CVEs
63
Critical
1,302
High
6.7
Avg CVSS

Yearly Trend

2026
122
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 52
2 Idccms 25
3 Ibm 23
4 Dedecms 14
5 Cisco 11
6 Jfinalcms Project 10
7 Flycms Project 9
8 Pligg 8
9 Enalean 8
10 Tipsandtricks Hq 8

All Cross-Site Request Forgery (CSRF) CVEs (2,379)

CVE-2024-53793
8.2

This vulnerability in eDoc Intelligence LLC's eDoc Easy Tables WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks ...

Dec 2, 2024
CVE-2024-52451
8.2

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Post Ideas plugin that can lead to SQL injection. Attackers can ...

Nov 20, 2024
CVE-2024-49617
8.2

This vulnerability in the Back Link Tracker WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Blind ...

Oct 20, 2024
CVE-2024-49615
8.2

A Cross-Site Request Forgery (CSRF) vulnerability in the SafetyForms WordPress plugin allows attackers to trick authenticated administrators into perf...

Oct 20, 2024
CVE-2024-49622
8.2

A Cross-Site Request Forgery (CSRF) vulnerability in the Apa Banner Slider WordPress plugin allows attackers to trick authenticated administrators int...

Oct 20, 2024
CVE-2024-29026
8.2

This CVE describes a Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability in Owncast versions 0.1.2 and prior. Attackers can exploit th...

Mar 20, 2024
CVE-2024-20255
8.2

An unauthenticated CSRF vulnerability in Cisco Expressway Series and TelePresence VCS SOAP API allows attackers to trick authenticated users into exec...

Feb 7, 2024
CVE-2021-41260
8.2

CVE-2021-41260 is a Cross-Site Request Forgery (CSRF) vulnerability in Galette, a membership management web application for non-profit organizations. ...

Dec 16, 2021
CVE-2021-32677
8.2

FastAPI versions below 0.65.2 are vulnerable to CSRF attacks when using cookie-based authentication with JSON payloads. The vulnerability allows attac...

Jun 9, 2021
CVE-2025-59541
8.1

This CSRF vulnerability in Chamilo LMS allows attackers to trick authenticated trainers into deleting projects within courses without their consent. T...

Mar 6, 2026
CVE-2026-25221
8.1

PolarLearn's OAuth 2.0 implementation for GitHub and Google login is vulnerable to Login CSRF due to missing state parameter validation. This allows a...

Feb 2, 2026
CVE-2025-14472
8.1

This CSRF vulnerability in Drupal Acquia Content Hub allows attackers to trick authenticated administrators into performing unintended actions by craf...

Jan 28, 2026
CVE-2025-13982
8.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Drupal Login Time Restriction module allows attackers to trick authenticated users into perfo...

Jan 28, 2026
CVE-2025-35030
8.1

This CVE describes a cross-site request forgery (CSRF) vulnerability in Medical Informatics Engineering Enterprise Health software. Unauthenticated at...

Sep 29, 2025
CVE-2025-7667
8.1

This CSRF vulnerability in the WordPress Restrict File Access plugin allows unauthenticated attackers to delete arbitrary files on the server by trick...

Jul 15, 2025
CVE-2024-4994
8.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in GitLab's GraphQL API that allows attackers to trick authenticated users into e...

Jun 20, 2025
CVE-2024-6719
8.1

This vulnerability in the Offload Videos WordPress plugin allows attackers to change plugin settings without the administrator's consent via Cross-Sit...

May 15, 2025
CVE-2025-28062
8.1

A Cross-Site Request Forgery vulnerability in ERPNEXT allows attackers to trick authenticated users into performing unauthorized actions like deleting...

May 5, 2025
CVE-2025-31689
8.1

This CSRF vulnerability in Drupal's GDPR module allows attackers to trick authenticated users into performing unintended actions without their consent...

Mar 31, 2025
CVE-2024-8065
8.1

A Cross-Site Request Forgery (CSRF) vulnerability in Danswer AI version 1.4.1 allows attackers to trick authenticated users into performing unauthoriz...

Mar 20, 2025
CVE-2024-8026
8.1

This CSRF vulnerability in netease-youdao/qanything's backend API allows attackers to trick authenticated users into performing unauthorized actions v...

Mar 20, 2025
CVE-2024-10906
8.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in eosphoros-ai/db-gpt version 0.6.0 where the server's CORS middleware allows al...

Mar 20, 2025
CVE-2024-13753
8.1

This CSRF vulnerability in the Ultimate Classified Listings WordPress plugin allows unauthenticated attackers to change victim email addresses by tric...

Feb 20, 2025
CVE-2020-10095
8.1

This Cross-Site Request Forgery (CSRF) vulnerability in Lexmark devices allows attackers to trick authenticated users into submitting malicious reques...

Feb 19, 2025
CVE-2024-13684
8.1

The Reset plugin for WordPress has a CSRF vulnerability that allows unauthenticated attackers to trick administrators into clicking malicious links th...

Feb 18, 2025
CVE-2024-56903
8.1

This vulnerability in Geovision GV-ASWeb allows attackers to modify POST requests to GET requests against critical account management functions. When ...

Feb 3, 2025
CVE-2024-55076
8.1

Grocy versions through 4.3.0 lack Cross-Site Request Forgery (CSRF) protection, allowing attackers to trick authenticated users into performing uninte...

Jan 6, 2025
CVE-2024-51484
8.1

Ampache versions before 7.0.1 have a CSRF vulnerability in token parsing when activating/deactivating controllers, allowing attackers to trick authent...

Nov 11, 2024
CVE-2024-51487
8.1

Ampache versions before 7.0.1 have a CSRF vulnerability in catalog activation/deactivation functions. Attackers can trick authenticated administrators...

Nov 11, 2024
CVE-2024-6862
8.1

This CSRF vulnerability in lunary-ai/lunary version 1.2.34 allows attackers to perform unauthorized actions like creating projects by exploiting overl...

Sep 13, 2024
CVE-2024-3983
8.1

The WooCommerce Customers Manager WordPress plugin before version 30.1 lacks CSRF protection on certain bulk actions, allowing attackers to trick logg...

Aug 1, 2024
CVE-2024-5167
8.1

This vulnerability in the CM Email Registration Blacklist and Whitelist WordPress plugin allows attackers to trick logged-in administrators into addin...

Jul 13, 2024
CVE-2024-38345
8.1

A cross-site request forgery (CSRF) vulnerability in Sola Testimonials WordPress plugin versions before 3.0.0 allows attackers to trick authenticated ...

Jul 4, 2024
CVE-2024-5712
8.1

A Cross-Site Request Forgery (CSRF) vulnerability in the stitionai/devika application allows attackers to trick authenticated users into performing un...

Jun 28, 2024
CVE-2024-4328
8.1

This CSRF vulnerability in parisneo/lollms-webui allows attackers to trick authenticated users into unknowingly clearing personality files via malicio...

Jun 10, 2024
CVE-2024-33830
8.1

CVE-2024-33830 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performi...

May 6, 2024
CVE-2024-29019
8.1

This CSRF vulnerability in ESPHome's dashboard component allows attackers to perform unauthorized configuration file operations (create, edit, delete)...

Apr 11, 2024
CVE-2024-28195
8.1

CVE-2024-28195 is a Cross-Site Request Forgery (CSRF) vulnerability in your_spotify, an open-source self-hosted Spotify tracking dashboard. Attackers ...

Mar 13, 2024
CVE-2022-3899
8.1

This CSRF vulnerability in the 3dprint WordPress plugin allows attackers to delete arbitrary files and directories on the server by tricking an authen...

Jan 16, 2024
CVE-2023-50774
8.1

This CSRF vulnerability in Jenkins HTMLResource Plugin allows attackers to trick authenticated users into executing malicious requests that delete arb...

Dec 13, 2023
CVE-2023-38130
8.1

A cross-site request forgery (CSRF) vulnerability in CubeCart e-commerce software allows unauthenticated remote attackers to delete data from the syst...

Nov 17, 2023
CVE-2023-43148
8.1

SPA-Cart 1.9.0.3 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to trick authenticated administrators into unknowing...

Oct 12, 2023
CVE-2023-32761
8.1

This CSRF vulnerability in Archer Platform allows authenticated attackers to execute arbitrary code via crafted requests. It affects Archer Platform v...

Jul 14, 2023
CVE-2023-37597
8.1

A Cross-Site Request Forgery (CSRF) vulnerability in Issabel PBX v4.0.0-6 allows remote attackers to delete user groups via forged requests, causing d...

Jul 11, 2023
CVE-2023-36690
8.1

This CSRF vulnerability in the WPLMS WordPress theme allows attackers to trick authenticated administrators into performing unintended actions. It aff...

Jul 11, 2023
CVE-2023-0870
8.1

This CVE describes a cross-site request forgery (CSRF) vulnerability in OpenNMS Meridian and Horizon monitoring platforms. Attackers can manipulate fo...

Mar 22, 2023
CVE-2023-27490
8.1

This vulnerability in NextAuth.js allows attackers to bypass authentication and log in as victims by intercepting and tampering with OAuth authorizati...

Mar 9, 2023
CVE-2022-1572
8.1

The HTML2WP WordPress plugin through version 1.0.0 contains an authorization bypass vulnerability in an AJAX endpoint that allows any authenticated us...

Jun 27, 2022
CVE-2022-33121
8.1

This CSRF vulnerability in MiniCMS v1.11 allows attackers to trick authenticated users into clicking malicious links that delete local .dat files. Any...

Jun 24, 2022
CVE-2022-1791
8.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the One Click Plugin Updater WordPress plugin. Attackers can trick logged-in a...

Jun 13, 2022

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,379 CVEs classified as CWE-352, with 63 rated critical and 1,302 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free