CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,348
Total CVEs
63
Critical
1,273
High
6.6
Avg CVSS

Yearly Trend

2026
119
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 48
2 Idccms 25
3 Ibm 20
4 Dedecms 14
5 Jfinalcms Project 10
6 Flycms Project 9
7 Cisco 9
8 Enalean 8
9 Tipsandtricks Hq 8
10 Pligg 8

All Cross-Site Request Forgery (CSRF) CVEs (2,348)

CVE-2023-2746
9.6

Rockwell Automation Enhanced HIM software has insufficient API protection with incorrect CORS settings, making it vulnerable to CSRF attacks. An attac...

Jul 11, 2023
CVE-2023-37277
9.6

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in XWiki Platform's REST API that allows attackers to execute arbitrary code when...

Jul 10, 2023
CVE-2022-42447
9.6

HCL Compass has a Cross-Origin Resource Sharing (CORS) vulnerability that allows attackers to trick authenticated users into making unauthorized reque...

Apr 2, 2023
CVE-2021-25010
9.6

This vulnerability in the Post Snippets WordPress plugin allows attackers to trick logged-in administrators into importing malicious code snippets wit...

Feb 28, 2022
CVE-2024-42764
9.4

Kashipara Bus Ticket Reservation System v1.0 has a CSRF vulnerability in /deleteTicket.php that allows attackers to trick authenticated users into per...

Aug 23, 2024
CVE-2025-30528
9.3

This vulnerability in the WordPress Awesome Logos plugin allows attackers to perform SQL injection via Cross-Site Request Forgery (CSRF). Attackers ca...

Mar 24, 2025
CVE-2024-50966
9.3

This CSRF vulnerability in dingfanzu CMS V1.0 allows attackers to trick authenticated administrators into performing unauthorized actions, specificall...

Nov 8, 2024
CVE-2021-41274
9.3

CVE-2021-41274 is a CSRF vulnerability in solidus_auth_devise that allows attackers to take over user accounts by tricking authenticated users into su...

Nov 17, 2021
CVE-2023-1722
9.1

Yoga Class Registration System 1.0 contains a cross-site request forgery (CSRF) vulnerability that allows administrators to execute arbitrary commands...

Jun 24, 2023
CVE-2023-23465
9.1

CVE-2023-23465 is a Cross-Site Request Forgery (CSRF) vulnerability in Media CP Media Control Panel that allows attackers to trick authenticated users...

Feb 15, 2023
CVE-2025-26206
9.0

A Cross-Site Request Forgery (CSRF) vulnerability in Sell Done Storefront v1.0 allows attackers to trick authenticated users into performing unintende...

Mar 3, 2025
CVE-2023-40572
9.0

CVE-2023-40572 is a Cross-Site Request Forgery (CSRF) vulnerability in XWiki Platform's create action that allows attackers to execute arbitrary scrip...

Aug 24, 2023
CVE-2021-24922
9.0

This vulnerability in the Pixel Cat WordPress plugin allows attackers to trick logged-in administrators into changing plugin settings without their co...

Dec 13, 2021
CVE-2023-39446
8.9

This is a Cross-Site Request Forgery (CSRF) vulnerability in web applications with weak user management. Attackers can craft malicious URLs that execu...

Sep 18, 2023
CVE-2026-25812
8.8

PlaciPy placement management system lacks CSRF protection while allowing credentialed CORS requests, enabling attackers to perform unauthorized action...

Feb 9, 2026
CVE-2025-68722
8.8

This CSRF vulnerability in Axigen Mail Server's WebAdmin interface allows attackers to craft malicious URLs that execute administrative actions when c...

Feb 5, 2026
CVE-2025-31413
8.8

This CSRF vulnerability in bdthemes Element Pack Elementor Addons allows attackers to trick authenticated WordPress administrators into performing uni...

Jan 22, 2026
CVE-2026-23622
8.8

This CSRF vulnerability in Easy!Appointments allows attackers to perform state-changing operations via crafted GET requests, bypassing CSRF protection...

Jan 15, 2026
CVE-2026-22194
8.8

GestSup versions up to 3.2.60 contain a CSRF vulnerability that allows attackers to trick authenticated users into performing unauthorized actions. An...

Jan 9, 2026
CVE-2022-50804
8.8

CVE-2022-50804 is a CSRF vulnerability in JM-DATA ONU JF511-TV version 1.0.67 that allows attackers to trick authenticated administrators into unknowi...

Dec 30, 2025
CVE-2024-30855
8.8

DedeCMS v5.7 contains a CSRF vulnerability in the makehtml_list_action.php file that allows attackers to trick authenticated administrators into perfo...

Dec 29, 2025
CVE-2025-68601
8.8

This CSRF vulnerability in the Five Star Restaurant Reservations WordPress plugin allows attackers to trick authenticated administrators into performi...

Dec 24, 2025
CVE-2025-68580
8.8

This CSRF vulnerability in the Advanced Classifieds & Directory Pro WordPress plugin allows attackers to trick authenticated administrators into perfo...

Dec 24, 2025
CVE-2025-68583
8.8

This CSRF vulnerability in the Tikweb Management Fast User Switching WordPress plugin allows attackers to trick authenticated administrators into perf...

Dec 24, 2025
CVE-2025-68584
8.8

This CSRF vulnerability in the Vimeotheque WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions ...

Dec 24, 2025
CVE-2025-68573
8.8

This CSRF vulnerability in the Simple Keyword to Link WordPress plugin allows attackers to trick authenticated administrators into performing unintend...

Dec 24, 2025
CVE-2025-68567
8.8

This CSRF vulnerability in the WordPress My auctions allegro plugin allows attackers to trick authenticated administrators into performing unintended ...

Dec 24, 2025
CVE-2025-68529
8.8

This CSRF vulnerability in WP Email Capture allows attackers to trick authenticated WordPress administrators into performing unintended actions. It af...

Dec 24, 2025
CVE-2025-67622
8.8

This vulnerability in the Evergreen Post Tweeter WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to S...

Dec 24, 2025
CVE-2025-67625
8.8

This CSRF vulnerability in the Trade Runner WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions...

Dec 24, 2025
CVE-2025-68434
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Open Source Point of Sale (OSPOS) allows unauthenticated attackers to create administrator accoun...

Dec 17, 2025
CVE-2025-66953
8.8

This CSRF vulnerability in narda miteq Uplink Power Control Unit UPC2 version 1.17 allows remote attackers to trick authenticated users into executing...

Dec 17, 2025
CVE-2025-65593
8.8

nopCommerce 4.90.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in its Schedule Tasks functionality. This allows attackers to trick auth...

Dec 16, 2025
CVE-2021-47730
8.8

Selea Targa IP OCR-ANPR cameras contain a CSRF vulnerability that allows attackers to create administrative accounts without authentication. When a lo...

Dec 9, 2025
CVE-2021-47723
8.8

CVE-2021-47723 is a cross-site request forgery vulnerability in STVS ProVision 5.9.10 that allows attackers to create new administrative users by tric...

Dec 9, 2025
CVE-2025-65573
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky software allows attackers to trick authenticated users into performing unintend...

Dec 9, 2025
CVE-2025-67469
8.8

This CSRF vulnerability in kubiq PDF Thumbnail Generator allows attackers to trick authenticated WordPress administrators into performing unintended a...

Dec 9, 2025
CVE-2025-67471
8.8

This CSRF vulnerability in the Quick Contact Form WordPress plugin allows attackers to trick authenticated administrators into performing unintended a...

Dec 9, 2025
CVE-2025-67472
8.8

This CSRF vulnerability in vcita's WordPress booking plugin allows attackers to trick authenticated administrators into performing unintended actions,...

Dec 9, 2025
CVE-2025-67473
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the CWW Companion WordPress plugin allows attackers to trick authenticated administrators into...

Dec 9, 2025
CVE-2025-67465
8.8

This CSRF vulnerability in QuantumCloud Simple Link Directory WordPress plugin allows attackers to trick authenticated administrators into performing ...

Dec 9, 2025
CVE-2025-66529
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the Ays Pro Chartify WordPress plugin allows attackers to trick authenticated administrators into...

Dec 9, 2025
CVE-2025-66531
8.8

This CSRF vulnerability in the Dimitri Grassi Salon booking system WordPress plugin allows attackers to trick authenticated administrators into perfor...

Dec 9, 2025
CVE-2025-64256
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Simple Folio WordPress plugin allows attackers to trick authenticated administrators into ...

Dec 9, 2025
CVE-2025-62739
8.8

This CSRF vulnerability in the WordPress Add Custom Codes plugin allows attackers to trick authenticated administrators into performing unintended act...

Dec 9, 2025
CVE-2025-12879
8.8

This CSRF vulnerability in the WordPress User Generator and Importer plugin allows unauthenticated attackers to create administrator accounts by trick...

Dec 5, 2025
CVE-2025-13871
8.8

This CSRF vulnerability in ObjectPlanet Opinio allows attackers to trick authenticated users into uploading files to the system, then access those fil...

Dec 2, 2025
CVE-2025-65840
8.8

PublicCMS V5.202506.b contains a CSRF vulnerability in the CkEditorAdminController that allows attackers to trick authenticated administrators into pe...

Dec 1, 2025
CVE-2025-56400
8.8

A CSRF vulnerability in Tuya SDK's OAuth implementation allows attackers to link their Amazon Alexa account to victims' Tuya accounts without consent....

Nov 24, 2025
CVE-2025-11087
8.8

The Zegen Core WordPress plugin up to version 2.0.1 has a CSRF vulnerability that allows unauthenticated attackers to upload arbitrary files to the se...

Nov 21, 2025

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,348 CVEs classified as CWE-352, with 63 rated critical and 1,273 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.6.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free