CWE-352: Cross-Site Request Forgery (CSRF)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Yearly Trend
Top Affected Vendors
All Cross-Site Request Forgery (CSRF) CVEs (2,353)
This CSRF vulnerability in WSO2 products allows attackers to trick authenticated users into performing unintended administrative actions by clicking m...
Nov 18, 2025A Cross-Site Request Forgery (CSRF) vulnerability in Simple-Faucet-Script v1.07 allows attackers to execute arbitrary code via crafted POST requests t...
Nov 12, 2025A cross-site request forgery (CSRF) vulnerability in QuLog Center allows attackers to trick authenticated users into performing unintended actions. Th...
Nov 7, 2025This CSRF vulnerability in the WP GDPR Cookie Consent WordPress plugin allows attackers to trick authenticated administrators into executing malicious...
Nov 6, 2025This vulnerability in the WordPress Block Country plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cro...
Nov 6, 2025This vulnerability in the Slick Google Map WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored ...
Nov 6, 2025This vulnerability in the WordPress wpNamedUsers plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cros...
Nov 6, 2025This vulnerability in the ZIPANG Simple Stripe WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Sto...
Nov 6, 2025This vulnerability allows attackers to perform unauthorized actions on behalf of authenticated users by exploiting the lack of CSRF protection in BLU-...
Oct 29, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the NikanWP WooCommerce Reporting plugin allows attackers to perform stored cross-site scripting ...
Oct 27, 2025This CSRF vulnerability in Simple Content Templates for WordPress allows attackers to trick authenticated administrators into performing unintended ac...
Oct 27, 2025This Cross-Site Request Forgery (CSRF) vulnerability in the Awesome Testimonials WordPress plugin allows attackers to inject malicious scripts that ex...
Oct 27, 2025This CSRF vulnerability in the WP Business Hours WordPress plugin allows attackers to trick authenticated administrators into performing unintended ac...
Oct 27, 2025This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the wpdevart Pricing Table builder WordPress plugin that leads to Stored Cross...
Oct 27, 2025A Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Brands for WooCommerce allows attackers to trick authenticated administrators into perf...
Oct 27, 2025This CSRF vulnerability in the Simple Registration for WooCommerce WordPress plugin allows unauthenticated attackers to trick administrators into appr...
Oct 25, 2025This CSRF vulnerability in the IndieAuth WordPress plugin allows attackers to trick authenticated users into approving malicious OAuth authorization r...
Oct 24, 2025Apache Geode's Management and Monitoring REST API is vulnerable to Cross-Site Request Forgery (CSRF) attacks via GET requests. An attacker who obtains...
Oct 18, 2025The Theme Editor WordPress plugin has a Cross-Site Request Forgery vulnerability that allows unauthenticated attackers to execute arbitrary code remot...
Oct 18, 2025The TextBuilder WordPress plugin (versions 1.0.0 to 1.1.1) has a CSRF vulnerability that allows unauthenticated attackers to trick administrators into...
Oct 3, 2025This CSRF vulnerability in LXD-UI allows attackers to create and start container instances without user consent by tricking authenticated users into s...
Oct 2, 2025A Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core WordPress plugin allows attackers to bypass authentication and perform unaut...
Sep 26, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the Anps Constructo WordPress theme allows attackers to trick authenticated users into performing...
Sep 22, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the ApusTheme Findgo WordPress theme allows attackers to trick authenticated users into performin...
Sep 22, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the CouponXxL WordPress theme allows attackers to trick authenticated users into performing unint...
Sep 22, 2025This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in multiple Ivanti security products that allows an unauthenticated remote attack...
Sep 9, 2025This Cross-Site Request Forgery (CSRF) vulnerability in the INVELITY MyGLS connect WordPress plugin allows attackers to trick authenticated administra...
Sep 5, 2025This CSRF vulnerability in the Video Share VOD WordPress plugin allows attackers to trick administrators into executing malicious actions. When exploi...
Aug 28, 2025This CSRF vulnerability in old-peanut Open-Shop allows attackers to trick authenticated users into submitting malicious POST requests, potentially exp...
Aug 20, 2025This CSRF vulnerability in Basix NEX-Forms WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions....
Aug 20, 2025A Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy WordPress plugin allows attackers to perform PHP object injection attacks. Th...
Aug 16, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the ApusTheme Findgo WordPress theme allows attackers to trick authenticated administrators into ...
Aug 14, 2025This CSRF vulnerability in MediaWiki's SecurePoll extension allows attackers to trick administrators into performing unauthorized sensitive actions li...
Jul 4, 2025A Cross-Site Request Forgery (CSRF) vulnerability in Infigo Software's IS-theme-companion WordPress plugin allows attackers to trick authenticated adm...
Jun 27, 2025A Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager WordPress plugin allows attackers to trick authenticated adminis...
Jun 20, 2025CVE-2025-41661 allows unauthenticated remote attackers to execute arbitrary commands with root privileges on affected devices due to missing CSRF prot...
Jun 11, 2025A Cross-Site Request Forgery (CSRF) vulnerability in Drupal's Restrict route by IP module allows attackers to trick authenticated administrators into ...
May 14, 2025A Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows attackers to trick authenticated users into performi...
May 2, 2025This CSRF vulnerability in the NewsBlogger WordPress theme allows unauthenticated attackers to trick administrators into executing malicious actions. ...
May 1, 2025A Cross-Site Request Forgery vulnerability in Zimbra Collaboration's GraphQL endpoint allows attackers to perform unauthorized operations when authent...
Apr 29, 2025This CSRF vulnerability in Moodle's Brickfield tool allows attackers to trick authenticated users into unknowingly submitting analysis requests. Any M...
Apr 25, 2025A Cross-Site Request Forgery (CSRF) vulnerability in WPSolr free WordPress plugin allows attackers to trick authenticated administrators into performi...
Apr 9, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the Purab Seo Meta Tags WordPress plugin allows attackers to trick authenticated administrators i...
Apr 9, 2025The WPFront User Role Editor WordPress plugin has a CSRF vulnerability in all versions up to 4.2.1 that allows unauthenticated attackers to change def...
Apr 8, 2025This CSRF vulnerability in Drupal Cache Utility allows attackers to trick authenticated users into performing unintended actions on their behalf. It a...
Mar 31, 2025This CSRF vulnerability in Drupal AI allows attackers to trick authenticated users into performing unintended actions on the Drupal site. It affects D...
Mar 31, 2025The Booknetic WordPress plugin before version 4.1.5 lacks CSRF protection when creating Staff accounts, allowing attackers to trick logged-in administ...
Mar 26, 2025This CSRF vulnerability in the EZ SQL Reports Shortcode Widget and DB Backup WordPress plugin allows attackers to execute arbitrary code on the server...
Mar 25, 2025This vulnerability allows non-admin users to execute arbitrary code remotely via CSRF attacks in open-webui versions up to 0.3.8. Attackers can craft ...
Mar 20, 2025A CSRF vulnerability in binary-husky/gpt_academic version 3.83 allows attackers to trick authenticated users into uploading malicious files without th...
Mar 20, 2025About Cross-Site Request Forgery (CSRF) (CWE-352)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Our database tracks 2,353 CVEs classified as CWE-352, with 63 rated critical and 1,278 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.6.
External reference: View CWE-352 on MITRE CWE →
Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities
Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.
Start Monitoring Free