CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,519
Total CVEs
68
Critical
1,435
High
6.8
Avg CVSS

Yearly Trend

2026
125
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 56
2 Ibm 27
3 Idccms 25
4 Netgear 17
5 Cisco 14
6 Dedecms 14
7 Jfinalcms Project 10
8 Flycms Project 9
9 Tipsandtricks Hq 8
10 Oracle 8

All Cross-Site Request Forgery (CSRF) CVEs (2,519)

CVE-2023-44478
7.1

This CSRF vulnerability in the WordPress Events Rich Snippets for Google plugin allows attackers to trick authenticated administrators into performing...

May 17, 2024
CVE-2024-3903
7.1

This vulnerability in the Add Custom CSS and JS WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that inject mal...

May 14, 2024
CVE-2024-34818
7.1

This Cross-Site Request Forgery (CSRF) vulnerability in the WebinarPress WordPress plugin allows attackers to trick authenticated administrators into ...

May 14, 2024
CVE-2024-4600
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in Socomec Net Vision version 7.20 allows attackers to trick authenticated users into performing una...

May 7, 2024
CVE-2024-34367
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Popup Box WordPress plugin that can lead to Cross-Site Scripting (XSS). At...

May 6, 2024
CVE-2024-33681
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress 'Regenerate post permalink' plugin that can lead to Cross-Site S...

Apr 29, 2024
CVE-2024-32958
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Slash Admin WordPress plugin that can lead to Cross-Site Scripting (XSS). ...

Apr 24, 2024
CVE-2024-32785
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in The Pack Elementor addons WordPress plugin allows attackers to trick authenticated users into per...

Apr 24, 2024
CVE-2024-32538
7.1

This vulnerability in the Easy CountDowner WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored ...

Apr 17, 2024
CVE-2024-32549
7.1

This CSRF vulnerability in the Microkid Related Posts WordPress plugin allows attackers to trick authenticated administrators into performing unintend...

Apr 17, 2024
CVE-2024-31093
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Broken Images plugin that can lead to Cross-Site Scripting (XSS)...

Apr 15, 2024
CVE-2024-30545
7.1

This vulnerability in the WordPress Social Author Bio plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored...

Apr 15, 2024
CVE-2024-31285
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Tooltip WordPress Tooltips plugin that can lead to Stored Cross-Site Scrip...

Apr 11, 2024
CVE-2024-2741
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in Planet IGS-4215-16T2S switches allows attackers to trick authenticated users into performing unau...

Apr 11, 2024
CVE-2024-31299
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the ReDi Restaurant Reservation WordPress plugin that can lead to Cross-Site S...

Apr 10, 2024
CVE-2024-31109
7.1

This CSRF vulnerability in the WooCommerce Social Media Share Buttons WordPress plugin allows attackers to trick authenticated administrators into per...

Apr 2, 2024
CVE-2024-29773
7.1

This CSRF vulnerability in the BizPrint WordPress plugin allows attackers to trick authenticated users into performing unintended actions, which can l...

Mar 27, 2024
CVE-2023-39311
7.1

This CSRF vulnerability in ThemeFusion Fusion Builder allows attackers to trick authenticated WordPress administrators into performing unintended acti...

Mar 27, 2024
CVE-2024-27968
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in the Optimole Super Page Cache for Cloudflare WordPress plugin allows attackers to perform stored ...

Mar 21, 2024
CVE-2024-27194
7.1

This vulnerability in the Fontific WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cross-Si...

Mar 16, 2024
CVE-2024-27197
7.1

This CSRF vulnerability in the BeePress WordPress plugin allows attackers to trick authenticated administrators into performing actions that inject ma...

Mar 16, 2024
CVE-2024-21752
7.1

This CSRF vulnerability in Ajax Search Lite WordPress plugin allows attackers to trick authenticated users into executing malicious actions, which can...

Feb 29, 2024
CVE-2024-24843
7.1

A Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Pro for Elementor allows attackers to trick authenticated administrators into performin...

Feb 21, 2024
CVE-2024-22287
7.1

This CSRF vulnerability in the Better Anchor Links WordPress plugin allows attackers to trick authenticated administrators into performing unintended ...

Jan 31, 2024
CVE-2022-41990
7.1

This vulnerability in the Vinoj Cardoza 3D Tag Cloud WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead ...

Jan 17, 2024
CVE-2023-47870
7.1

This CSRF vulnerability in the wpForo Forum WordPress plugin allows attackers to force all users to log out by tricking authenticated administrators i...

Nov 30, 2023
CVE-2023-36682
7.1

This CSRF vulnerability in the Schema Pro WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. ...

Nov 30, 2023
CVE-2023-33333
7.1

This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to site-wide Cross-Site Scripting (XSS) in the Comp...

Nov 30, 2023
CVE-2023-47550
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress plugin 'Donations Made Easy – Smart Donations' that allows att...

Nov 14, 2023
CVE-2023-31230
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Haoqisir Baidu Tongji generator WordPress plugin that can lead to Stored C...

Nov 13, 2023
CVE-2023-35877
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Extra User Details plugin that allows attackers to perform store...

Nov 13, 2023
CVE-2023-40335
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Cleverwise Daily Quotes WordPress plugin that leads to Stored Cross-Site S...

Nov 13, 2023
CVE-2023-46201
7.1

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the WordPress 'Auto Login New User After Registration' plugin that can lead to...

Nov 13, 2023
CVE-2023-47516
7.1

This vulnerability in the Stark Digital Category Post List Widget WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attac...

Nov 13, 2023
CVE-2023-45047
7.1

This CSRF vulnerability in the LeadSquared Suite WordPress plugin allows attackers to trick authenticated administrators into performing unintended ac...

Oct 12, 2023
CVE-2023-23671
7.1

This CSRF vulnerability in the Muneeb Layer Slider WordPress plugin allows attackers to trick authenticated administrators into performing unauthorize...

Jul 11, 2023
CVE-2023-32960
7.1

This CSRF vulnerability in UpdraftPlus WordPress Backup Plugin allows attackers to trick authenticated administrators into executing malicious actions...

Jun 22, 2023
CVE-2023-23795
7.1

This CSRF vulnerability in the Muneeb Form Builder WordPress plugin allows attackers to trick authenticated administrators into performing unintended ...

Jun 22, 2023
CVE-2023-33926
7.1

This CSRF vulnerability in the Supsystic Easy Google Maps WordPress plugin allows attackers to trick authenticated administrators into performing unin...

May 28, 2023
CVE-2023-23890
7.1

This CSRF vulnerability in the WP Airbnb Review Slider WordPress plugin allows attackers to trick authenticated administrators into performing unautho...

May 20, 2023
CVE-2023-2444
7.1

This CSRF vulnerability in Rockwell Automation's FactoryTalk Vantagepoint allows attackers to trick authenticated users into performing unauthorized a...

May 11, 2023
CVE-2023-23790
7.1

This CSRF vulnerability in the Pods WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. It aff...

May 3, 2023
CVE-2023-28718
7.1

CVE-2023-28718 is a Cross-Site Request Forgery (CSRF) vulnerability in Osprey Pump Controller version 1.01 that allows attackers to perform unauthoriz...

Mar 28, 2023
CVE-2021-25108
7.1

This vulnerability in the IP2Location Country Blocker WordPress plugin allows attackers to trick logged-in administrators into blocking arbitrary coun...

Feb 7, 2022
CVE-2021-25095
7.1

The IP2Location Country Blocker WordPress plugin before version 2.26.5 lacks proper authorization and CSRF protection in its AJAX endpoint, allowing a...

Feb 7, 2022
CVE-2021-22224
7.1

This CSRF vulnerability in GitLab's GraphQL API allows attackers to execute mutations as authenticated users without their consent. It affects GitLab ...

Jul 7, 2021
CVE-2020-10771
7.1

CVE-2020-10771 is a CSRF vulnerability in Infinispan 10 that allows attackers to perform unauthorized actions via GET requests. This affects systems r...

Jun 2, 2021
CVE-2021-21652
7.1

This CSRF vulnerability in Jenkins Xray plugin allows attackers to trick authenticated users into unknowingly connecting Jenkins to attacker-controlle...

May 11, 2021
CVE-2021-21655
7.1

This CSRF vulnerability in Jenkins P4 Plugin allows attackers to trick authenticated users into connecting Jenkins to a malicious Perforce server with...

May 11, 2021
CVE-2020-25263
7.1

This CSRF vulnerability in PyroCMS allows attackers to trick authenticated admin users into unknowingly deleting arbitrary plugins via a malicious lin...

Oct 8, 2020

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,519 CVEs classified as CWE-352, with 68 rated critical and 1,435 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.8.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free