CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,510
Total CVEs
68
Critical
1,426
High
6.8
Avg CVSS

Yearly Trend

2026
125
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 56
2 Ibm 27
3 Idccms 25
4 Netgear 17
5 Dedecms 14
6 Cisco 13
7 Jfinalcms Project 10
8 Flycms Project 9
9 Oretnom23 8
10 Pligg 8

All Cross-Site Request Forgery (CSRF) CVEs (2,510)

CVE-2024-53778
7.1

This CSRF vulnerability in the Essential Breadcrumbs WordPress plugin allows attackers to trick authenticated administrators into performing actions w...

Nov 30, 2024
CVE-2024-53736
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Custom Shortcode Sidebars plugin allows attackers to perform stored cross-site scri...

Nov 28, 2024
CVE-2024-52421
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress WP Popup Window Maker plugin allows attackers to perform actions as authenticated u...

Nov 19, 2024
CVE-2024-52388
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Hebrew Date plugin allows attackers to perform stored cross-site scripting (XSS) at...

Nov 19, 2024
CVE-2024-51654
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the APK.Support APK Downloader WordPress plugin that can lead to Stored Cross-...

Nov 19, 2024
CVE-2024-51656
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Flash Show And Hide Box plugin allows attackers to perform stored cross-site script...

Nov 19, 2024
CVE-2024-51649
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Patrick Lumumba Mobilize WordPress plugin allows attackers to perform stored cross-site scrip...

Nov 19, 2024
CVE-2024-51652
7.1

This CSRF vulnerability in the WordPress Skip To plugin allows attackers to trick authenticated administrators into performing actions that inject mal...

Nov 19, 2024
CVE-2024-51641
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Advanced PDF Generator WordPress plugin that can lead to Stored Cross-Site...

Nov 19, 2024
CVE-2024-51643
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Amazon Associate Filter WordPress plugin allows attackers to perform stored cross-site script...

Nov 19, 2024
CVE-2024-51645
7.1

This CSRF vulnerability in ThemeFuse Maintenance Mode WordPress plugin allows attackers to trick authenticated administrators into performing unintend...

Nov 19, 2024
CVE-2024-51637
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Admin SMS Alert plugin that can lead to Stored Cross-Site Script...

Nov 19, 2024
CVE-2024-51639
7.1

This vulnerability in the Hints Naver Blog WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored ...

Nov 19, 2024
CVE-2024-51633
7.1

This CSRF vulnerability in the WordPress Simple Page Specific Sidebars plugin allows attackers to trick authenticated administrators into performing u...

Nov 19, 2024
CVE-2024-51635
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress While Loading plugin allows attackers to perform stored cross-site scripting (XSS) ...

Nov 19, 2024
CVE-2024-51631
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Sticky Social Bar plugin allows attackers to trick authenticated administrators int...

Nov 19, 2024
CVE-2024-50533
7.1

This CSRF vulnerability in the WordPress Domain Sharding plugin allows attackers to trick authenticated administrators into performing unintended acti...

Nov 19, 2024
CVE-2024-52424
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress wp-login customizer plugin allows attackers to inject malicious scripts that execut...

Nov 18, 2024
CVE-2024-51658
7.1

This CSRF vulnerability in WP Course Manager allows attackers to trick authenticated administrators into performing actions that inject malicious scri...

Nov 14, 2024
CVE-2024-51679
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the GentleSource Appointmind WordPress plugin allows attackers to perform stored cross-site scrip...

Nov 14, 2024
CVE-2024-51687
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Platform.Ly Official WordPress plugin that can lead to Stored Cross-Site S...

Nov 14, 2024
CVE-2024-51688
7.1

This vulnerability in the FraudLabs Pro SMS Verification WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that l...

Nov 14, 2024
CVE-2024-51630
7.1

This vulnerability in the Responsive Flickr Gallery WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead t...

Nov 9, 2024
CVE-2024-49629
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Endless Posts Navigation plugin that can lead to Stored Cross-Si...

Oct 20, 2024
CVE-2024-49335
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Edush Maxim GoogleDrive folder list WordPress plugin allows attackers to inject malicious scr...

Oct 20, 2024
CVE-2024-49313
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the RudeStan VKontakte Wall Post WordPress plugin allows attackers to inject malicious scripts th...

Oct 17, 2024
CVE-2024-49220
7.1

This vulnerability in the WordPress Cookie Scanner plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cr...

Oct 17, 2024
CVE-2024-49223
7.1

This vulnerability in the WordPress CJ Change Howdy plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored C...

Oct 17, 2024
CVE-2024-48048
7.1

This vulnerability in the WSIFY WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cross-Site ...

Oct 17, 2024
CVE-2024-20421
7.1

An unauthenticated remote attacker can perform CSRF attacks against Cisco ATA 190 Series Analog Telephone Adapter web management interfaces. This allo...

Oct 16, 2024
CVE-2024-6959
7.1

This vulnerability in parisneo/lollms-webui version 9.8 allows attackers to cause a Denial of Service (DoS) by uploading specially crafted audio files...

Oct 13, 2024
CVE-2024-44028
7.1

This CSRF vulnerability in the NiceJob WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions, whi...

Oct 6, 2024
CVE-2024-47644
7.1

This CSRF vulnerability in Copyscape Premium WordPress plugin allows attackers to trick authenticated administrators into executing malicious actions,...

Oct 5, 2024
CVE-2024-44064
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the LikeBtn Like Button Rating WordPress plugin allows attackers to perform Cross-Site Scripting ...

Sep 17, 2024
CVE-2024-43301
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Fonts Plugin for WordPress allows attackers to perform stored cross-site scripting (XSS) atta...

Aug 26, 2024
CVE-2024-43255
7.1

This CSRF vulnerability in the MyBookTable Bookstore WordPress plugin allows attackers to trick authenticated administrators into performing unintende...

Aug 26, 2024
CVE-2024-5287
7.1

This CSRF vulnerability in the wp-affiliate-platform WordPress plugin allows attackers to trick authenticated administrators into unknowingly changing...

Jul 13, 2024
CVE-2024-37213
7.1

This CSRF vulnerability in Ali2Woo Lite WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions, wh...

Jul 12, 2024
CVE-2024-35773
7.1

This CSRF vulnerability in the WordPress Comment Reply Email plugin allows attackers to trick authenticated administrators into performing actions wit...

Jul 12, 2024
CVE-2024-37306
7.1

This is a Cross-Site Request Forgery (CSRF) vulnerability in CVAT that allows attackers to trick authenticated users into performing unauthorized data...

Jun 13, 2024
CVE-2024-4531
7.1

The Business Card WordPress plugin through version 1.0.0 lacks CSRF protection on certain endpoints, allowing attackers to trick authenticated users i...

May 27, 2024
CVE-2023-44478
7.1

This CSRF vulnerability in the WordPress Events Rich Snippets for Google plugin allows attackers to trick authenticated administrators into performing...

May 17, 2024
CVE-2024-3903
7.1

This vulnerability in the Add Custom CSS and JS WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that inject mal...

May 14, 2024
CVE-2024-34818
7.1

This Cross-Site Request Forgery (CSRF) vulnerability in the WebinarPress WordPress plugin allows attackers to trick authenticated administrators into ...

May 14, 2024
CVE-2024-4600
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in Socomec Net Vision version 7.20 allows attackers to trick authenticated users into performing una...

May 7, 2024
CVE-2024-34367
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Popup Box WordPress plugin that can lead to Cross-Site Scripting (XSS). At...

May 6, 2024
CVE-2024-33681
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress 'Regenerate post permalink' plugin that can lead to Cross-Site S...

Apr 29, 2024
CVE-2024-32958
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Slash Admin WordPress plugin that can lead to Cross-Site Scripting (XSS). ...

Apr 24, 2024
CVE-2024-32785
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in The Pack Elementor addons WordPress plugin allows attackers to trick authenticated users into per...

Apr 24, 2024
CVE-2024-32538
7.1

This vulnerability in the Easy CountDowner WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored ...

Apr 17, 2024

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,510 CVEs classified as CWE-352, with 68 rated critical and 1,426 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.8.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free