CWE-352: Cross-Site Request Forgery (CSRF)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Yearly Trend
Top Affected Vendors
All Cross-Site Request Forgery (CSRF) CVEs (2,465)
A Cross-Site Request Forgery (CSRF) vulnerability in Kashipara Music Management System v1.0 allows attackers to trick authenticated users into perform...
Aug 28, 2024This vulnerability involves predictable CSRF tokens that allow attackers to craft malicious requests. When victims unknowingly trigger these requests,...
Feb 6, 2024A Cross-Site Request Forgery (CSRF) vulnerability in ePolicy Orchestrator (ePO) allows low-privileged remote users to add new administrator accounts b...
Nov 17, 2023This is a Cross-Site Request Forgery (CSRF) vulnerability in Jenkins where insufficient URL escaping allows attackers to trick authenticated users int...
Jun 14, 2023A CSRF vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to trick authenticated users into performing unauthorized ...
Jul 27, 2022This CSRF vulnerability in Jenkins Recipe Plugin allows attackers to trick authenticated users into making unintended HTTP requests to attacker-contro...
Jun 30, 2022A CSRF vulnerability in Jenkins CloudBees AWS Credentials Plugin allows attackers with Overall/Read permission to trick authenticated users into conne...
Mar 15, 2022A cross-site request forgery (CSRF) vulnerability in Zyxel ARMOR Z1/Z2 router firmware allows attackers to execute arbitrary commands by tricking auth...
Feb 24, 2022This vulnerability in the WP Extra File Types WordPress plugin allows attackers to trick logged-in administrators into changing plugin settings withou...
Jan 24, 2022This CSRF vulnerability in Rockoa v1.9.8 allows authenticated attackers to create unauthorized administrator accounts by tricking legitimate users int...
Dec 22, 2021CVE-2021-42097 is a Cross-Site Request Forgery (CSRF) vulnerability in GNU Mailman that allows privilege escalation. An attacker can obtain a CSRF tok...
Oct 21, 2021This is a Cross-Site Request Forgery (CSRF) vulnerability in Dada Mail that allows attackers to perform unauthorized actions as authenticated users. W...
Sep 20, 2021This CSRF vulnerability in Cybozu Garoon allows authenticated attackers to trick administrators into performing unintended actions by exploiting their...
Aug 18, 2021This CSRF vulnerability in DamiCMS v6.0.6 allows attackers to create unauthorized admin accounts by tricking authenticated administrators into visitin...
Aug 12, 2021CVE-2021-21407 is a Cross-Site Request Forgery (CSRF) vulnerability in Combodo iTop that allows attackers to bypass CSRF token validation through a tr...
Jul 21, 2021A Cross-Site Request Forgery (CSRF) vulnerability in Star Practice Management Web allows attackers to change user privileges, including granting thems...
Jan 29, 2021This CSRF vulnerability in EgavilanMedia User Registration & Login System 1.0 allows attackers to trick authenticated users into submitting malicious ...
Dec 21, 2020This CSRF vulnerability in Lansweeper allows low-level authenticated users to escalate their privileges by tricking administrators into performing uni...
Sep 30, 2020CVE-2020-2196 is a Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Selenium Plugin that allows attackers to perform administrative actions ...
Jun 3, 2020This CSRF vulnerability in Smartvista BackOffice allows attackers to trick authenticated users into performing unintended actions via crafted GET requ...
Sep 18, 2025A CSRF vulnerability in saTECH BCU firmware version 2.1.3 allows attackers to trick authenticated administrators into executing unauthorized actions. ...
Mar 28, 2025This vulnerability allows attackers to inject malicious HTML attributes into Jupyter notebooks in GitLab, enabling them to perform arbitrary HTTP POST...
Mar 28, 2022This CSRF vulnerability in the Muslim Prayer Time BD WordPress plugin allows attackers to trick authenticated administrators into resetting plugin set...
Jun 26, 2024The WP Prayer WordPress plugin through version 2.0.9 lacks CSRF protection when updating settings, allowing attackers to trick logged-in administrator...
May 15, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the ValvePress Automatic WordPress plugin. Attackers can trick authenticated a...
Apr 22, 2024This stored cross-site scripting vulnerability in Pandora FMS allows attackers to inject malicious scripts into the Create event section. When users v...
Feb 15, 2023This vulnerability affects all versions of the sqlite-web package, allowing attackers to perform unauthorized sensitive actions through Cross-Site Req...
Sep 8, 2021This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in McAfee Data Loss Prevention ePO extension. It allows authenticated attackers t...
Aug 13, 2020Ghost CMS versions 5.101.6 through 6.19.2 have incomplete CSRF protections in the session verification endpoint, allowing attackers to use one-time co...
Mar 7, 2026A CSRF vulnerability in Socomec DIRIS Digiware M-70's WEBVIEW-M functionality allows attackers to craft malicious webpages that trick authenticated us...
Dec 1, 2025A CSRF vulnerability in PHPGurukul Student Record System v3.2 allows attackers to trick authenticated administrators into executing unauthorized accou...
Nov 18, 2025Mercku M6a devices allow attackers to change administrator passwords via cross-site request forgery (CSRF) attacks when accessed from the local networ...
Oct 22, 2025This CSRF vulnerability in the Realtyna Organic IDX WordPress plugin allows attackers to trick authenticated administrators into performing unintended...
Aug 20, 2025A CSRF-to-XSS vulnerability in the UCRM Client Signup Plugin allows attackers to execute arbitrary JavaScript in administrator sessions, potentially l...
Jun 29, 2025This CSRF vulnerability in the Insert Headers And Footers WordPress plugin allows attackers to trick administrators into clicking malicious links that...
Apr 19, 2025This CSRF vulnerability in Fortinet FortiNDR allows remote unauthenticated attackers to execute unauthorized actions via crafted HTTP GET requests. It...
Mar 11, 2025This CSRF vulnerability in TYPO3's backend allows attackers to trick authenticated backend users into performing unauthorized actions via malicious li...
Jan 14, 2025This CSRF vulnerability in Teedy allows attackers to perform unauthorized administrative actions via a forged POST request to /api/user/admin. It affe...
Jan 13, 2025This CSRF vulnerability in CodeIgniter 3.1.13 allows attackers to trick authenticated administrators into unknowingly changing their own passwords. At...
Oct 15, 2024This vulnerability in the ArtPlacer Widget WordPress plugin allows attackers to trick logged-in administrators into executing malicious actions via Cr...
Jul 19, 2024This CSRF vulnerability in WP STAGING Pro WordPress Backup Plugin allows unauthenticated attackers to trick administrators into executing malicious re...
Jun 14, 2024This vulnerability in Werkzeug's debugger allows attackers to execute arbitrary code on a developer's machine if they can trick the developer into int...
May 6, 2024The MF Gig Calendar WordPress plugin through version 1.2.1 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers...
May 6, 2024This vulnerability allows authenticated attackers in Dolibarr ERP CRM to steal session cookies and CSRF tokens from other users through crafted web pa...
Apr 17, 2024This is a Cross-Site Request Forgery (CSRF) vulnerability in LedgerSMB that allows attackers to trick authenticated database administrators into unkno...
Feb 2, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Siemens RUGGEDCOM ROX industrial routers. An attacker can trick authenticated ...
Jul 11, 2023This CSRF vulnerability in the Groundhogg WordPress plugin allows authenticated attackers to trick administrators into performing actions that modify ...
May 20, 2023The Change wp-admin login WordPress plugin before version 1.1.0 has an authorization bypass and missing CSRF protection in its settings update functio...
May 30, 2022Shopware versions before 5.7.9 have a CSRF token validation flaw that allows attackers to bypass CSRF protection. This enables unauthorized actions to...
Apr 28, 2022This vulnerability in XWiki allows attackers to determine whether an email address has an associated user account and identify the corresponding usern...
Feb 4, 2022About Cross-Site Request Forgery (CSRF) (CWE-352)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Our database tracks 2,465 CVEs classified as CWE-352, with 67 rated critical and 1,383 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.
External reference: View CWE-352 on MITRE CWE →
Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities
Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.
Start Monitoring Free