CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,466
Total CVEs
67
Critical
1,384
High
6.7
Avg CVSS

Yearly Trend

2026
123
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 55
2 Idccms 25
3 Ibm 24
4 Dedecms 14
5 Cisco 12
6 Jfinalcms Project 10
7 Flycms Project 9
8 Oracle 8
9 Enalean 8
10 Oretnom23 8

All Cross-Site Request Forgery (CSRF) CVEs (2,466)

CVE-2021-32732
7.5

This vulnerability in XWiki allows attackers to determine whether an email address has an associated user account and identify the corresponding usern...

Feb 4, 2022
CVE-2022-0154
7.5

This Cross-Site Request Forgery (CSRF) vulnerability in GitLab allows attackers to trick authenticated users into unknowingly importing GitHub project...

Jan 18, 2022
CVE-2021-24981
7.5

The Directorist WordPress plugin before version 7.0.6.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to trick auth...

Dec 21, 2021
CVE-2021-23050
7.5

This vulnerability affects F5 BIG-IP Advanced WAF, ASM, and NGINX App Protect when configured with CSRF-enabled policies. An attacker can send special...

Sep 14, 2021
CVE-2021-26296
7.5

Apache MyFaces Core uses cryptographically weak CSRF tokens in default configurations, allowing attackers to potentially predict future token values a...

Feb 19, 2021
CVE-2025-49237
7.4

This CSRF vulnerability in the POEditor WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions, sp...

Jun 6, 2025
CVE-2025-28954
7.4

A Cross-Site Request Forgery (CSRF) vulnerability in the wphobby Backwp WordPress plugin allows attackers to trick authenticated administrators into p...

Jun 6, 2025
CVE-2025-46439
7.4

A Cross-Site Request Forgery (CSRF) vulnerability in the Vladimir Prelovac Plugin Central WordPress plugin allows attackers to trick authenticated adm...

Apr 24, 2025
CVE-2025-39544
7.4

This CSRF vulnerability in Bill Minozzi WP Tools WordPress plugin allows attackers to trick authenticated administrators into performing unintended ac...

Apr 16, 2025
CVE-2024-26153
7.4

CVE-2024-26153 is a CSRF vulnerability in ETIC Telecom Remote Access Server (RAS) that allows attackers to trick authenticated users into submitting m...

Jan 17, 2025
CVE-2022-20853
7.4

This CSRF vulnerability in Cisco Expressway Series and TelePresence VCS REST API allows unauthenticated remote attackers to trick authenticated users ...

Nov 15, 2024
CVE-2024-37940
7.4

This CSRF vulnerability in Seraphinite Accelerator WordPress plugin allows attackers to trick authenticated administrators into performing unintended ...

Jul 12, 2024
CVE-2024-27694
7.4

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the /system/share/ztree_category_edit endpoint. This allows attackers to tri...

Mar 4, 2024
CVE-2022-0088
7.4

CVE-2022-0088 is a Cross-Site Request Forgery (CSRF) vulnerability in YOURLS URL shortener software versions prior to 1.8.3. This allows attackers to ...

Apr 3, 2022
CVE-2021-21241
7.4

This vulnerability in Flask-Security-Too allows attackers to steal authentication tokens via CSRF attacks on unprotected GET requests to /login and /c...

Jan 11, 2021
CVE-2020-5745
7.4

CVE-2020-5745 is a cross-site request forgery (CSRF) vulnerability in TCExam that allows attackers to trick authenticated users into performing uninte...

May 7, 2020
CVE-2026-25649
7.3

This vulnerability allows authenticated users in Traccar GPS tracking systems to steal OAuth 2.0 authorization codes via open redirect in OIDC endpoin...

Feb 23, 2026
CVE-2023-5934
7.3

This CSRF vulnerability in the Travelpayouts WordPress plugin allows attackers to trick logged-in administrators into unknowingly changing plugin sett...

May 15, 2025
CVE-2024-56924
7.3

This CSRF vulnerability in Code Astro Internet Banking System 2.0.0 allows attackers to execute arbitrary JavaScript on the admin page by tricking adm...

Jan 22, 2025
CVE-2024-5185
7.3

EmbedAI applications are vulnerable to data poisoning attacks via CSRF due to insecure session management and weak CORS policies. Attackers can trick ...

May 29, 2024
CVE-2024-2395
7.3

The Bulgarisation for WooCommerce WordPress plugin has a CSRF vulnerability that allows unauthenticated attackers to trick administrators into perform...

Mar 12, 2024
CVE-2017-20045
7.3

This critical CSRF vulnerability in Navetti PricePoint 4.6.0.0 allows attackers to trick authenticated users into performing unintended actions by sen...

Jun 13, 2022
CVE-2024-3593
7.2

The UberMenu WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to 3.8.3. This allows unauthenticated attackers to del...

Jun 22, 2024
CVE-2026-28477
7.1

OpenClaw versions before 2026.2.14 have an OAuth state validation bypass in the manual Chutes login flow that allows attackers to bypass CSRF protecti...

Mar 5, 2026
CVE-2026-22355
7.1

This vulnerability in the Simple XML Sitemap WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Store...

Jan 22, 2026
CVE-2025-14615
7.1

This CSRF vulnerability in the DASHBOARD BUILDER WordPress plugin allows unauthenticated attackers to trick administrators into modifying SQL queries ...

Jan 14, 2026
CVE-2025-31054
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Themefy Bloggie WordPress theme allows attackers to inject malicious scripts via reflected XS...

Dec 31, 2025
CVE-2025-49028
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in Zoho ZeptoMail WordPress plugin allows attackers to inject malicious scripts that become stored X...

Dec 31, 2025
CVE-2025-49353
7.1

This CSRF vulnerability in the WordPress Noindex by Path plugin allows attackers to trick authenticated administrators into performing unintended acti...

Dec 31, 2025
CVE-2025-49354
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Recent Posts From Each Category plugin allows attackers to inject malicious scripts...

Dec 31, 2025
CVE-2025-68885
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Page Carbajal Custom Post Status WordPress plugin allows attackers to perform stored cross-si...

Dec 31, 2025
CVE-2025-49342
7.1

This CSRF vulnerability in the Wolfgang Häfelinger Custom Style WordPress plugin allows attackers to trick authenticated administrators into performi...

Dec 31, 2025
CVE-2025-49343
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in Socialprofilr Social Profilr WordPress plugin allows attackers to inject malicious scripts that e...

Dec 31, 2025
CVE-2025-49344
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress SensitiveTagCloud plugin allows attackers to inject malicious scripts that execute ...

Dec 31, 2025
CVE-2025-49345
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WP-EasyArchives WordPress plugin allows attackers to inject malicious scripts that execute wh...

Dec 31, 2025
CVE-2025-59137
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the eLEOPARD Behance Portfolio Manager WordPress plugin allows attackers to inject malicious scri...

Dec 31, 2025
CVE-2025-49346
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Simple Archive Generator plugin allows attackers to trick authenticated administrat...

Dec 31, 2025
CVE-2025-59131
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Hoernerfranz WP-CalDav2ICS WordPress plugin allows attackers to perform unauthorized actions ...

Dec 30, 2025
CVE-2025-1927
7.1

This CSRF vulnerability in Restajet Online Food Delivery System allows attackers to trick authenticated users into performing unintended actions on th...

Dec 19, 2025
CVE-2025-65203
7.1

KeePassXC-Browser versions through 1.9.9.2 automatically fill or prompt to fill stored credentials into documents rendered under browser-enforced CSP ...

Dec 17, 2025
CVE-2025-34429
7.1

This CSRF vulnerability in 1Panel allows attackers to change the web service port when authenticated users visit malicious pages. Affected users are t...

Dec 10, 2025
CVE-2025-34410
7.1

This CSRF vulnerability in 1Panel allows attackers to change authenticated users' usernames without consent via malicious webpages. When exploited, vi...

Dec 10, 2025
CVE-2025-67534
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Jacques Malgrange Rencontre WordPress plugin allows attackers to perform stored cross-site sc...

Dec 9, 2025
CVE-2025-63030
7.1

This CSRF vulnerability in the WordPress New User Approve plugin allows attackers to trick administrators into performing unintended actions. Attacker...

Dec 9, 2025
CVE-2025-49341
7.1

This Cross-Site Request Forgery (CSRF) vulnerability in PDF Creator Lite WordPress plugin allows attackers to trick authenticated administrators into ...

Dec 9, 2025
CVE-2025-49347
7.1

This CSRF vulnerability in the WP sIFR WordPress plugin allows attackers to trick authenticated administrators into executing malicious actions, leadi...

Dec 9, 2025
CVE-2025-49351
7.1

This CSRF vulnerability in the WordPress Create Posts & Terms plugin allows attackers to trick authenticated administrators into performing unintended...

Dec 9, 2025
CVE-2025-60075
7.1

This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Reflected Cross-Site Scripting (XSS) in the Alle...

Oct 29, 2025
CVE-2025-62986
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the FanBridge WordPress plugin that allows attackers to inject malicious scrip...

Oct 27, 2025
CVE-2025-62005
7.1

This CSRF vulnerability in SUMO Memberships for WooCommerce allows attackers to trick authenticated administrators into performing unintended actions....

Oct 22, 2025

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,466 CVEs classified as CWE-352, with 67 rated critical and 1,384 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free