CWE-352: Cross-Site Request Forgery (CSRF)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Yearly Trend
Top Affected Vendors
All Cross-Site Request Forgery (CSRF) CVEs (2,526)
This vulnerability in the IP2Location Country Blocker WordPress plugin allows attackers to trick logged-in administrators into blocking arbitrary coun...
Feb 7, 2022The IP2Location Country Blocker WordPress plugin before version 2.26.5 lacks proper authorization and CSRF protection in its AJAX endpoint, allowing a...
Feb 7, 2022This CSRF vulnerability in GitLab's GraphQL API allows attackers to execute mutations as authenticated users without their consent. It affects GitLab ...
Jul 7, 2021CVE-2020-10771 is a CSRF vulnerability in Infinispan 10 that allows attackers to perform unauthorized actions via GET requests. This affects systems r...
Jun 2, 2021This CSRF vulnerability in Jenkins Xray plugin allows attackers to trick authenticated users into unknowingly connecting Jenkins to attacker-controlle...
May 11, 2021This CSRF vulnerability in Jenkins P4 Plugin allows attackers to trick authenticated users into connecting Jenkins to a malicious Perforce server with...
May 11, 2021This CSRF vulnerability in PyroCMS allows attackers to trick authenticated admin users into unknowingly deleting arbitrary plugins via a malicious lin...
Oct 8, 2020This CSRF vulnerability in SourceCodester Stock Management System v1.0 allows attackers to change authenticated users' usernames without their consent...
Sep 2, 2020This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Rumpus FTP Web File Manager's web settings interface. Attackers can trick auth...
Feb 10, 2020This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in McAfee Endpoint Security's ePO extension that allows attackers to execute arbi...
Nov 12, 2020This CSRF vulnerability in open-webui/open-webui v0.3.8 allows attackers to trick authenticated users into performing sensitive actions like deleting ...
Mar 20, 2025This vulnerability in the Newsletter Popup WordPress plugin allows attackers to trick logged-in administrators into deleting subscribers without their...
May 16, 2024This CSRF vulnerability in edu Business Solutions Print Shop Pro WebDesk allows attackers to trick authenticated users into performing unintended acti...
Jan 8, 2026This CSRF vulnerability in RiteCMS v3.1.0 allows attackers to create or edit website pages without authorization by tricking authenticated administrat...
Dec 17, 2025This Cross-Site Request Forgery (CSRF) vulnerability in Kiteworks MFT allows attackers to trick administrators into browsing malicious pages, potentia...
Nov 29, 2025A Cross-Site Request Forgery (CSRF) vulnerability in HCL Glovius Cloud allows attackers to trick authenticated users into performing unintended action...
Nov 20, 2025This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability affecting omni-administrator users in Liferay Portal and DXP. Attackers can trick...
Aug 20, 2025This CSRF vulnerability in Drupal Google Tag allows attackers to trick authenticated administrators into performing unauthorized actions, such as modi...
Mar 31, 2025Wangmarket v4.10 to v5.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the AgencyUserController component. This allows attackers to tr...
Feb 21, 2025SAP Commerce sets authentication cookies with SameSite=None by default, making them vulnerable to cross-site request forgery (CSRF) attacks. This affe...
Feb 11, 2025PwnDoc lacks CSRF protection, allowing attackers to perform actions on behalf of logged-in users without their consent. This affects all PwnDoc instan...
Jan 20, 2025The Favicon Generator WordPress plugin before version 2.1 contains two critical vulnerabilities: missing file upload validation and missing CSRF prote...
Sep 13, 2024CVE-2024-45172 is a cross-site request forgery (CSRF) vulnerability in za-internet C-MOR Video Surveillance web interface that allows attackers to tri...
Sep 4, 2024A Cross-Site Request Forgery (CSRF) vulnerability in Kashipara Hotel Management System v1.0 allows attackers to trick authenticated administrators int...
Aug 22, 2024Parse Dashboard versions 7.3.0-alpha.42 through 9.0.0-alpha.7 lack CSRF protection on the AI Agent API endpoint. This allows attackers to craft malici...
Feb 25, 2026IBM DB2 Recovery Expert for Linux, UNIX and Windows version 5.5 Interim Fix 002 is vulnerable to cross-site request forgery (CSRF). This allows attack...
Feb 17, 2026This CSRF vulnerability in Open eClass allows attackers to trick authenticated teachers into performing unauthorized actions like modifying assignment...
Feb 3, 2026CVE-2025-70899 is a Cross-Site Request Forgery vulnerability in PHPgurukul Online Course Registration v3.1 that allows attackers to perform unauthoriz...
Jan 22, 2026CVE-2021-47830 is a CSRF vulnerability in GetSimple CMS My SMTP Contact Plugin 1.1.1 that allows attackers to trick authenticated administrators into ...
Jan 21, 2026CVE-2021-47754 is a cross-site request forgery (CSRF) vulnerability in Arunna 1.0.0 that allows attackers to manipulate authenticated users into submi...
Jan 15, 2026A Cross-Site Request Forgery (CSRF) vulnerability in Everest Backup WordPress plugin allows attackers to trick authenticated administrators into perfo...
Dec 31, 2025This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in ETL Systems Ltd DEXTRA Series Digital L-Band Distribution System web managemen...
Dec 26, 2025This cross-site request forgery vulnerability in Sony SNC-CX600W IP cameras allows attackers to trick authenticated users into performing unintended o...
Nov 25, 2025This CSRF vulnerability in Magewell Pro Convert allows attackers to create arbitrary user accounts without authorization by tricking authenticated adm...
Nov 24, 2025A cross-site request forgery (CSRF) vulnerability in LogStare Collector allows attackers to trick authenticated users into performing unintended opera...
Nov 21, 2025This CSRF vulnerability in HasThemes WP Plugin Manager allows attackers to trick authenticated WordPress administrators into performing unintended act...
Nov 13, 2025This CSRF vulnerability in the WordPress Auto Prune Posts plugin allows attackers to trick authenticated administrators into performing unintended act...
Nov 13, 2025A Cross-Site Request Forgery (CSRF) vulnerability in xxl-api v1.3.0 allows attackers to trick authenticated administrators into executing unauthorized...
Nov 12, 2025This CSRF vulnerability in Pet Grooming Management Software allows attackers to trick authenticated administrators into changing their passwords witho...
Nov 7, 2025CVE-2025-63716 is a Cross-Site Request Forgery vulnerability in SourceCodester Leads Manager Tool v1.0 that allows attackers to trick authenticated us...
Nov 7, 2025This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Liferay Portal's Headless API that allows attackers to execute any Headless AP...
Oct 27, 2025This CVE describes a cross-site request forgery vulnerability in Rockwell Automation products where missing CSRF checks allow attackers to modify conf...
Oct 14, 2025IBM Storage TS4500 Library versions 1.11.0.0 and 2.11.0.0 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to trick aut...
Sep 27, 2025This CVE describes an authenticated CSRF vulnerability in the web management interface of Shenzhen C-Data Technology Co. FD602GW-DX-R410 routers. An a...
Sep 23, 2025This CSRF vulnerability in the BP Disable Activation Reloaded WordPress plugin allows attackers to trick authenticated administrators into performing ...
Sep 22, 2025This CSRF vulnerability in the RIS Version Switcher WordPress plugin allows attackers to trick authenticated administrators into performing unintended...
Sep 22, 2025This CSRF vulnerability in the Woocommerce Gifts Product WordPress plugin allows attackers to trick authenticated administrators into performing unint...
Sep 5, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the Simasicher SimaCookie WordPress plugin allows attackers to perform stored cross-site scriptin...
Sep 5, 2025A Cross-Site Request Forgery (CSRF) vulnerability in the Woocommerce Notify Updated Product WordPress plugin allows attackers to perform stored cross-...
Sep 5, 2025This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Bevy Event service that allows attackers to trick authenticated users into...
Aug 27, 2025About Cross-Site Request Forgery (CSRF) (CWE-352)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Our database tracks 2,526 CVEs classified as CWE-352, with 68 rated critical and 1,442 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.8.
External reference: View CWE-352 on MITRE CWE →
Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities
Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.
Start Monitoring Free