CWE-352: Cross-Site Request Forgery (CSRF)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Yearly Trend
Top Affected Vendors
All Cross-Site Request Forgery (CSRF) CVEs (2,519)
This CSRF vulnerability in the WordPress Events Rich Snippets for Google plugin allows attackers to trick authenticated administrators into performing...
May 17, 2024This vulnerability in the Add Custom CSS and JS WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that inject mal...
May 14, 2024This Cross-Site Request Forgery (CSRF) vulnerability in the WebinarPress WordPress plugin allows attackers to trick authenticated administrators into ...
May 14, 2024A Cross-Site Request Forgery (CSRF) vulnerability in Socomec Net Vision version 7.20 allows attackers to trick authenticated users into performing una...
May 7, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Popup Box WordPress plugin that can lead to Cross-Site Scripting (XSS). At...
May 6, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress 'Regenerate post permalink' plugin that can lead to Cross-Site S...
Apr 29, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Slash Admin WordPress plugin that can lead to Cross-Site Scripting (XSS). ...
Apr 24, 2024A Cross-Site Request Forgery (CSRF) vulnerability in The Pack Elementor addons WordPress plugin allows attackers to trick authenticated users into per...
Apr 24, 2024This vulnerability in the Easy CountDowner WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored ...
Apr 17, 2024This CSRF vulnerability in the Microkid Related Posts WordPress plugin allows attackers to trick authenticated administrators into performing unintend...
Apr 17, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Broken Images plugin that can lead to Cross-Site Scripting (XSS)...
Apr 15, 2024This vulnerability in the WordPress Social Author Bio plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored...
Apr 15, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Tooltip WordPress Tooltips plugin that can lead to Stored Cross-Site Scrip...
Apr 11, 2024A Cross-Site Request Forgery (CSRF) vulnerability in Planet IGS-4215-16T2S switches allows attackers to trick authenticated users into performing unau...
Apr 11, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the ReDi Restaurant Reservation WordPress plugin that can lead to Cross-Site S...
Apr 10, 2024This CSRF vulnerability in the WooCommerce Social Media Share Buttons WordPress plugin allows attackers to trick authenticated administrators into per...
Apr 2, 2024This CSRF vulnerability in the BizPrint WordPress plugin allows attackers to trick authenticated users into performing unintended actions, which can l...
Mar 27, 2024This CSRF vulnerability in ThemeFusion Fusion Builder allows attackers to trick authenticated WordPress administrators into performing unintended acti...
Mar 27, 2024A Cross-Site Request Forgery (CSRF) vulnerability in the Optimole Super Page Cache for Cloudflare WordPress plugin allows attackers to perform stored ...
Mar 21, 2024This vulnerability in the Fontific WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cross-Si...
Mar 16, 2024This CSRF vulnerability in the BeePress WordPress plugin allows attackers to trick authenticated administrators into performing actions that inject ma...
Mar 16, 2024This CSRF vulnerability in Ajax Search Lite WordPress plugin allows attackers to trick authenticated users into executing malicious actions, which can...
Feb 29, 2024A Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Pro for Elementor allows attackers to trick authenticated administrators into performin...
Feb 21, 2024This CSRF vulnerability in the Better Anchor Links WordPress plugin allows attackers to trick authenticated administrators into performing unintended ...
Jan 31, 2024This vulnerability in the Vinoj Cardoza 3D Tag Cloud WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead ...
Jan 17, 2024This CSRF vulnerability in the wpForo Forum WordPress plugin allows attackers to force all users to log out by tricking authenticated administrators i...
Nov 30, 2023This CSRF vulnerability in the Schema Pro WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. ...
Nov 30, 2023This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to site-wide Cross-Site Scripting (XSS) in the Comp...
Nov 30, 2023This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress plugin 'Donations Made Easy – Smart Donations' that allows att...
Nov 14, 2023This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Haoqisir Baidu Tongji generator WordPress plugin that can lead to Stored C...
Nov 13, 2023This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Extra User Details plugin that allows attackers to perform store...
Nov 13, 2023This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Cleverwise Daily Quotes WordPress plugin that leads to Stored Cross-Site S...
Nov 13, 2023This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress 'Auto Login New User After Registration' plugin that can lead to...
Nov 13, 2023This vulnerability in the Stark Digital Category Post List Widget WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attac...
Nov 13, 2023This CSRF vulnerability in the LeadSquared Suite WordPress plugin allows attackers to trick authenticated administrators into performing unintended ac...
Oct 12, 2023This CSRF vulnerability in the Muneeb Layer Slider WordPress plugin allows attackers to trick authenticated administrators into performing unauthorize...
Jul 11, 2023This CSRF vulnerability in UpdraftPlus WordPress Backup Plugin allows attackers to trick authenticated administrators into executing malicious actions...
Jun 22, 2023This CSRF vulnerability in the Muneeb Form Builder WordPress plugin allows attackers to trick authenticated administrators into performing unintended ...
Jun 22, 2023This CSRF vulnerability in the Supsystic Easy Google Maps WordPress plugin allows attackers to trick authenticated administrators into performing unin...
May 28, 2023This CSRF vulnerability in the WP Airbnb Review Slider WordPress plugin allows attackers to trick authenticated administrators into performing unautho...
May 20, 2023This CSRF vulnerability in Rockwell Automation's FactoryTalk Vantagepoint allows attackers to trick authenticated users into performing unauthorized a...
May 11, 2023This CSRF vulnerability in the Pods WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. It aff...
May 3, 2023CVE-2023-28718 is a Cross-Site Request Forgery (CSRF) vulnerability in Osprey Pump Controller version 1.01 that allows attackers to perform unauthoriz...
Mar 28, 2023This vulnerability in the IP2Location Country Blocker WordPress plugin allows attackers to trick logged-in administrators into blocking arbitrary coun...
Feb 7, 2022The IP2Location Country Blocker WordPress plugin before version 2.26.5 lacks proper authorization and CSRF protection in its AJAX endpoint, allowing a...
Feb 7, 2022This CSRF vulnerability in GitLab's GraphQL API allows attackers to execute mutations as authenticated users without their consent. It affects GitLab ...
Jul 7, 2021CVE-2020-10771 is a CSRF vulnerability in Infinispan 10 that allows attackers to perform unauthorized actions via GET requests. This affects systems r...
Jun 2, 2021This CSRF vulnerability in Jenkins Xray plugin allows attackers to trick authenticated users into unknowingly connecting Jenkins to attacker-controlle...
May 11, 2021This CSRF vulnerability in Jenkins P4 Plugin allows attackers to trick authenticated users into connecting Jenkins to a malicious Perforce server with...
May 11, 2021This CSRF vulnerability in PyroCMS allows attackers to trick authenticated admin users into unknowingly deleting arbitrary plugins via a malicious lin...
Oct 8, 2020About Cross-Site Request Forgery (CSRF) (CWE-352)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Our database tracks 2,519 CVEs classified as CWE-352, with 68 rated critical and 1,435 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.8.
External reference: View CWE-352 on MITRE CWE →
Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities
Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.
Start Monitoring Free