CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,533
Total CVEs
68
Critical
1,449
High
6.8
Avg CVSS

Yearly Trend

2026
125
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 57
2 Ibm 27
3 Idccms 25
4 Netgear 17
5 Cisco 14
6 Dedecms 14
7 Jfinalcms Project 10
8 Flycms Project 9
9 Pligg 8
10 Tipsandtricks Hq 8

All Cross-Site Request Forgery (CSRF) CVEs (2,533)

CVE-2025-56311
6.5

This CVE describes an authenticated CSRF vulnerability in the web management interface of Shenzhen C-Data Technology Co. FD602GW-DX-R410 routers. An a...

Sep 23, 2025
CVE-2025-57983
6.5

This CSRF vulnerability in the BP Disable Activation Reloaded WordPress plugin allows attackers to trick authenticated administrators into performing ...

Sep 22, 2025
CVE-2025-57902
6.5

This CSRF vulnerability in the RIS Version Switcher WordPress plugin allows attackers to trick authenticated administrators into performing unintended...

Sep 22, 2025
CVE-2025-58878
6.5

This CSRF vulnerability in the Woocommerce Gifts Product WordPress plugin allows attackers to trick authenticated administrators into performing unint...

Sep 5, 2025
CVE-2025-58869
6.5

A Cross-Site Request Forgery (CSRF) vulnerability in the Simasicher SimaCookie WordPress plugin allows attackers to perform stored cross-site scriptin...

Sep 5, 2025
CVE-2025-58856
6.5

A Cross-Site Request Forgery (CSRF) vulnerability in the Woocommerce Notify Updated Product WordPress plugin allows attackers to perform stored cross-...

Sep 5, 2025
CVE-2025-54598
6.5

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the Bevy Event service that allows attackers to trick authenticated users into...

Aug 27, 2025
CVE-2025-43745
6.5

This CSRF vulnerability in Liferay Portal and DXP allows remote attackers to perform unauthorized actions on behalf of authenticated users by exploiti...

Aug 19, 2025
CVE-2025-53249
6.5

This CSRF vulnerability in the Build App Online WordPress plugin allows attackers to trick authenticated administrators into performing unintended act...

Aug 14, 2025
CVE-2025-50847
6.5

A Cross-Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3 allows attackers to manipulate user sessions by adding products to comparison list...

Jul 31, 2025
CVE-2025-50586
6.5

StudentManage v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing unint...

Jul 18, 2025
CVE-2025-54033
6.5

This CSRF vulnerability in the BlocksWP Theme Builder For Elementor WordPress plugin allows attackers to trick authenticated administrators into perfo...

Jul 16, 2025
CVE-2025-50369
6.5

A Cross-Site Request Forgery vulnerability in PHPGurukul Medical Card Generation System 1.0 allows attackers to trick authenticated administrators int...

Jun 27, 2025
CVE-2024-8286
6.5

This Cross-Site Request Forgery (CSRF) vulnerability in the WebToffee GDPR Cookie Consent WordPress plugin allows attackers to trick logged-in adminis...

May 15, 2025
CVE-2025-39563
6.5

This CSRF vulnerability in WP Trio Conditional Payments for WooCommerce allows attackers to trick authenticated administrators into performing uninten...

Apr 16, 2025
CVE-2025-31751
6.5

A Cross-Site Request Forgery (CSRF) vulnerability in the Breaking News WP WordPress plugin allows attackers to trick authenticated administrators into...

Apr 1, 2025
CVE-2025-20228
6.5

A Cross-Site Request Forgery (CSRF) vulnerability in Splunk Enterprise and Splunk Cloud Platform allows low-privileged users without admin or power ro...

Mar 26, 2025
CVE-2024-8736
6.5

This CSRF vulnerability in lollms-webui allows attackers to cause denial of service by exploiting file upload endpoints. Attackers can append extra ch...

Mar 20, 2025
CVE-2024-10481
6.5

A Cross-Site Request Forgery (CSRF) vulnerability in ComfyUI versions up to v0.2.2 allows attackers to create malicious websites that, when visited by...

Mar 20, 2025
CVE-2024-35138
6.5

IBM Security Verify Access Appliance and Container versions 10.0.0 through 10.0.8 contain a cross-site request forgery (CSRF) vulnerability. This allo...

Feb 4, 2025
CVE-2024-12774
6.5

The Altra Side Menu WordPress plugin through version 2.0 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers t...

Jan 27, 2025
CVE-2024-38790
6.5

This CSRF vulnerability in the Smartsupp WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. I...

Jan 2, 2025
CVE-2024-56005
6.5

This CSRF vulnerability in the Posti Shipping WordPress plugin allows attackers to trick authenticated administrators into performing unintended actio...

Dec 16, 2024
CVE-2024-41776
6.5

IBM Cognos Controller versions 11.0.0 and 11.0.1 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to trick authenticate...

Dec 3, 2024
CVE-2024-9665
6.5

This CSRF vulnerability in Zimbra's GraphQL endpoint allows attackers to trick authenticated users into executing malicious GraphQL queries via crafte...

Nov 22, 2024
CVE-2023-0737
6.5

This CSRF vulnerability in wallabag allows attackers to trick authenticated users into unknowingly submitting requests to delete their own accounts. A...

Nov 15, 2024
CVE-2021-27704
6.5

CVE-2021-27704 is an incorrect access control vulnerability in Appspace 6.2.4 that allows attackers to bypass authentication via the password reset pa...

Nov 12, 2024
CVE-2024-41744
6.5

IBM CICS TX Standard 11.1 has a cross-site request forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing una...

Nov 1, 2024
CVE-2024-48031
6.5

This CSRF vulnerability in the Sumit Surai Featured Posts with Multiple Custom Groups WordPress plugin allows attackers to trick authenticated adminis...

Oct 17, 2024
CVE-2024-8047
6.5

The Visual Sound WordPress plugin through version 1.06 lacks CSRF protection in its settings update functionality. This allows attackers to trick logg...

Sep 17, 2024
CVE-2024-7817
6.5

The Misiek Photo Album WordPress plugin through version 1.4.3 lacks CSRF protection on certain album deletion functions, allowing attackers to trick a...

Sep 12, 2024
CVE-2024-7820
6.5

The ILC Thickbox WordPress plugin through version 1.0 lacks CSRF protection when updating settings, allowing attackers to trick logged-in administrato...

Sep 12, 2024
CVE-2024-7859
6.5

The Visual Sound WordPress plugin through version 1.03 lacks CSRF protection in its settings update functionality. This allows attackers to trick logg...

Sep 12, 2024
CVE-2024-20486
6.5

This CSRF vulnerability in Cisco ISE's web management interface allows unauthenticated remote attackers to trick authenticated users into executing ma...

Aug 21, 2024
CVE-2024-42476
6.5

This CVE describes a CSRF vulnerability in the OAuth library for Nim programming language. When compiled with certain compiler flags like -d:danger or...

Aug 15, 2024
CVE-2024-6496
6.5

The Light Poll WordPress plugin through version 1.0.0 lacks Cross-Site Request Forgery (CSRF) protection when deleting polls. This allows attackers to...

Aug 1, 2024
CVE-2024-1747
6.5

This vulnerability in the WooCommerce Customers Manager WordPress plugin allows any authenticated user, even with low privileges like subscriber, to p...

Aug 1, 2024
CVE-2024-6412
6.5

The HTML Forms WordPress plugin before version 1.3.34 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to t...

Jul 31, 2024
CVE-2023-38001
6.5

IBM Aspera Orchestrator 4.0.1 has a cross-site request forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing...

Jul 30, 2024
CVE-2024-6490
6.5

This CSRF vulnerability in the Master Slider WordPress plugin allows attackers to trick authenticated administrators into unknowingly submitting malic...

Jul 26, 2024
CVE-2024-40601
6.5

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the MediaWikiChat extension for MediaWiki. Attackers can trick authenticated u...

Jul 7, 2024
CVE-2024-27717
6.5

This Cross-Site Request Forgery (CSRF) vulnerability in Eskooly Free Online School Management Software allows attackers to trick authenticated users i...

Jul 5, 2024
CVE-2021-45785
6.5

This CSRF vulnerability in TruDesk Help Desk/Ticketing Solution v1.1.11 allows attackers to force privileged users to restart the server via a crafted...

Jun 24, 2024
CVE-2024-4382
6.5

This CSRF vulnerability in the CB (legacy) WordPress plugin allows attackers to trick logged-in administrators into performing unauthorized bulk actio...

Jun 21, 2024
CVE-2024-31612
6.5

Emlog Pro 2.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in twitter.php that can be combined with Cross-Site Scripting (XSS) to access...

Jun 10, 2024
CVE-2024-34958
6.5

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via the banner man...

May 16, 2024
CVE-2023-0336
6.5

The OoohBoi Steroids for Elementor WordPress plugin before version 2.1.5 contains CSRF and broken access control vulnerabilities. These allow attacker...

Mar 27, 2023
CVE-2023-20113
6.5

This CSRF vulnerability in Cisco SD-WAN vManage allows unauthenticated attackers to trick authenticated users into performing malicious actions via ma...

Mar 23, 2023
CVE-2022-41296
6.5

This CVE describes a cross-site request forgery (CSRF) vulnerability in IBM Db2U database software. An attacker could trick authenticated users into p...

Dec 12, 2022
CVE-2024-1211
6.4

This vulnerability allows cross-site request forgery (CSRF) attacks against GitLab instances configured to use JWT as an OmniAuth provider. Attackers ...

Jan 31, 2025

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,533 CVEs classified as CWE-352, with 68 rated critical and 1,449 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.8.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free