CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,353
Total CVEs
63
Critical
1,278
High
6.6
Avg CVSS

Yearly Trend

2026
119
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 51
2 Idccms 25
3 Ibm 20
4 Dedecms 14
5 Jfinalcms Project 10
6 Flycms Project 9
7 Cisco 9
8 Enalean 8
9 Tipsandtricks Hq 8
10 Pligg 8

All Cross-Site Request Forgery (CSRF) CVEs (2,353)

CVE-2025-6670
8.8

This CSRF vulnerability in WSO2 products allows attackers to trick authenticated users into performing unintended administrative actions by clicking m...

Nov 18, 2025
CVE-2025-57310
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Simple-Faucet-Script v1.07 allows attackers to execute arbitrary code via crafted POST requests t...

Nov 12, 2025
CVE-2025-58469
8.8

A cross-site request forgery (CSRF) vulnerability in QuLog Center allows attackers to trick authenticated users into performing unintended actions. Th...

Nov 7, 2025
CVE-2025-53316
8.8

This CSRF vulnerability in the WP GDPR Cookie Consent WordPress plugin allows attackers to trick authenticated administrators into executing malicious...

Nov 6, 2025
CVE-2025-48077
8.8

This vulnerability in the WordPress Block Country plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cro...

Nov 6, 2025
CVE-2025-48078
8.8

This vulnerability in the Slick Google Map WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored ...

Nov 6, 2025
CVE-2025-48083
8.8

This vulnerability in the WordPress wpNamedUsers plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cros...

Nov 6, 2025
CVE-2025-48085
8.8

This vulnerability in the ZIPANG Simple Stripe WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Sto...

Nov 6, 2025
CVE-2025-12479
8.8

This vulnerability allows attackers to perform unauthorized actions on behalf of authenticated users by exploiting the lack of CSRF protection in BLU-...

Oct 29, 2025
CVE-2025-62957
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the NikanWP WooCommerce Reporting plugin allows attackers to perform stored cross-site scripting ...

Oct 27, 2025
CVE-2025-62958
8.8

This CSRF vulnerability in Simple Content Templates for WordPress allows attackers to trick authenticated administrators into performing unintended ac...

Oct 27, 2025
CVE-2025-62933
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Awesome Testimonials WordPress plugin allows attackers to inject malicious scripts that ex...

Oct 27, 2025
CVE-2025-62934
8.8

This CSRF vulnerability in the WP Business Hours WordPress plugin allows attackers to trick authenticated administrators into performing unintended ac...

Oct 27, 2025
CVE-2025-62886
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the wpdevart Pricing Table builder WordPress plugin that leads to Stored Cross...

Oct 27, 2025
CVE-2025-62890
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Brands for WooCommerce allows attackers to trick authenticated administrators into perf...

Oct 27, 2025
CVE-2025-12095
8.8

This CSRF vulnerability in the Simple Registration for WooCommerce WordPress plugin allows unauthenticated attackers to trick administrators into appr...

Oct 25, 2025
CVE-2025-12028
8.8

This CSRF vulnerability in the IndieAuth WordPress plugin allows attackers to trick authenticated users into approving malicious OAuth authorization r...

Oct 24, 2025
CVE-2025-47410
8.8

Apache Geode's Management and Monitoring REST API is vulnerable to Cross-Site Request Forgery (CSRF) attacks via GET requests. An attacker who obtains...

Oct 18, 2025
CVE-2025-9890
8.8

The Theme Editor WordPress plugin has a Cross-Site Request Forgery vulnerability that allows unauthenticated attackers to execute arbitrary code remot...

Oct 18, 2025
CVE-2025-9213
8.8

The TextBuilder WordPress plugin (versions 1.0.0 to 1.1.1) has a CSRF vulnerability that allows unauthenticated attackers to trick administrators into...

Oct 3, 2025
CVE-2025-54286
8.8

This CSRF vulnerability in LXD-UI allows attackers to create and start container instances without user consent by tricking authenticated users into s...

Oct 2, 2025
CVE-2025-60111
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core WordPress plugin allows attackers to bypass authentication and perform unaut...

Sep 26, 2025
CVE-2025-58244
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the Anps Constructo WordPress theme allows attackers to trick authenticated users into performing...

Sep 22, 2025
CVE-2025-58250
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the ApusTheme Findgo WordPress theme allows attackers to trick authenticated users into performin...

Sep 22, 2025
CVE-2025-58013
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the CouponXxL WordPress theme allows attackers to trick authenticated users into performing unint...

Sep 22, 2025
CVE-2025-55147
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in multiple Ivanti security products that allows an unauthenticated remote attack...

Sep 9, 2025
CVE-2025-58833
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the INVELITY MyGLS connect WordPress plugin allows attackers to trick authenticated administra...

Sep 5, 2025
CVE-2025-7812
8.8

This CSRF vulnerability in the Video Share VOD WordPress plugin allows attackers to trick administrators into executing malicious actions. When exploi...

Aug 28, 2025
CVE-2025-50902
8.8

This CSRF vulnerability in old-peanut Open-Shop allows attackers to trick authenticated users into submitting malicious POST requests, potentially exp...

Aug 20, 2025
CVE-2025-49399
8.8

This CSRF vulnerability in Basix NEX-Forms WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions....

Aug 20, 2025
CVE-2025-49895
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy WordPress plugin allows attackers to perform PHP object injection attacks. Th...

Aug 16, 2025
CVE-2025-53587
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the ApusTheme Findgo WordPress theme allows attackers to trick authenticated administrators into ...

Aug 14, 2025
CVE-2025-53483
8.8

This CSRF vulnerability in MediaWiki's SecurePoll extension allows attackers to trick administrators into performing unauthorized sensitive actions li...

Jul 4, 2025
CVE-2025-53277
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Infigo Software's IS-theme-companion WordPress plugin allows attackers to trick authenticated adm...

Jun 27, 2025
CVE-2025-52825
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager WordPress plugin allows attackers to trick authenticated adminis...

Jun 20, 2025
CVE-2025-41661
8.8

CVE-2025-41661 allows unauthenticated remote attackers to execute arbitrary commands with root privileges on affected devices due to missing CSRF prot...

Jun 11, 2025
CVE-2025-47701
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Drupal's Restrict route by IP module allows attackers to trick authenticated administrators into ...

May 14, 2025
CVE-2024-11142
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows attackers to trick authenticated users into performi...

May 2, 2025
CVE-2025-1305
8.8

This CSRF vulnerability in the NewsBlogger WordPress theme allows unauthenticated attackers to trick administrators into executing malicious actions. ...

May 1, 2025
CVE-2025-32354
8.8

A Cross-Site Request Forgery vulnerability in Zimbra Collaboration's GraphQL endpoint allows attackers to perform unauthorized operations when authent...

Apr 29, 2025
CVE-2025-3638
8.8

This CSRF vulnerability in Moodle's Brickfield tool allows attackers to trick authenticated users into unknowingly submitting analysis requests. Any M...

Apr 25, 2025
CVE-2025-31036
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in WPSolr free WordPress plugin allows attackers to trick authenticated administrators into performi...

Apr 9, 2025
CVE-2025-31023
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the Purab Seo Meta Tags WordPress plugin allows attackers to trick authenticated administrators i...

Apr 9, 2025
CVE-2025-3064
8.8

The WPFront User Role Editor WordPress plugin has a CSRF vulnerability in all versions up to 4.2.1 that allows unauthenticated attackers to change def...

Apr 8, 2025
CVE-2025-31690
8.8

This CSRF vulnerability in Drupal Cache Utility allows attackers to trick authenticated users into performing unintended actions on their behalf. It a...

Mar 31, 2025
CVE-2025-31677
8.8

This CSRF vulnerability in Drupal AI allows attackers to trick authenticated users into performing unintended actions on the Drupal site. It affects D...

Mar 31, 2025
CVE-2024-13146
8.8

The Booknetic WordPress plugin before version 4.1.5 lacks CSRF protection when creating Staff accounts, allowing attackers to trick logged-in administ...

Mar 26, 2025
CVE-2025-2319
8.8

This CSRF vulnerability in the EZ SQL Reports Shortcode Widget and DB Backup WordPress plugin allows attackers to execute arbitrary code on the server...

Mar 25, 2025
CVE-2024-7806
8.8

This vulnerability allows non-admin users to execute arbitrary code remotely via CSRF attacks in open-webui versions up to 0.3.8. Attackers can craft ...

Mar 20, 2025
CVE-2024-10819
8.8

A CSRF vulnerability in binary-husky/gpt_academic version 3.83 allows attackers to trick authenticated users into uploading malicious files without th...

Mar 20, 2025

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,353 CVEs classified as CWE-352, with 63 rated critical and 1,278 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.6.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free