CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,357
Total CVEs
63
Critical
1,280
High
6.6
Avg CVSS

Yearly Trend

2026
121
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 51
2 Idccms 25
3 Ibm 21
4 Dedecms 14
5 Jfinalcms Project 10
6 Flycms Project 9
7 Cisco 9
8 Enalean 8
9 Tipsandtricks Hq 8
10 Pligg 8

All Cross-Site Request Forgery (CSRF) CVEs (2,357)

CVE-2024-13913
8.8

This CSRF vulnerability in the InstaWP Connect WordPress plugin allows unauthenticated attackers to execute arbitrary PHP code on affected servers by ...

Mar 14, 2025
CVE-2025-25907
8.8

CVE-2025-25907 is a Cross-Site Request Forgery vulnerability in tianti v2.3 that allows attackers to trick authenticated users into performing uninten...

Mar 10, 2025
CVE-2024-11640
8.8

The VikRentCar WordPress plugin has a CSRF vulnerability that allows attackers to escalate privileges and upload arbitrary files. Attackers can trick ...

Mar 8, 2025
CVE-2024-51144
8.8

This CSRF vulnerability in Ampache allows attackers to trick authenticated users into performing unintended actions by sending malicious requests. It ...

Mar 5, 2025
CVE-2025-1306
8.8

This CSRF vulnerability in the Newscrunch WordPress theme allows unauthenticated attackers to upload arbitrary files by tricking administrators into c...

Mar 4, 2025
CVE-2025-25967
8.8

Acora CMS version 10.1.1 has a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing unau...

Mar 3, 2025
CVE-2025-1687
8.8

This CSRF vulnerability in the Cardealer WordPress theme allows unauthenticated attackers to trick administrators into clicking malicious links that c...

Feb 28, 2025
CVE-2025-27276
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the lizeipe Photo Gallery (Responsive) WordPress plugin allows attackers to trick authenticated a...

Feb 24, 2025
CVE-2024-13315
8.8

This CSRF vulnerability in the Shopwarden WordPress plugin allows attackers to trick administrators into clicking malicious links that can change plug...

Feb 18, 2025
CVE-2024-13852
8.8

The Option Editor WordPress plugin version 1.0 has a CSRF vulnerability that allows unauthenticated attackers to trick administrators into clicking ma...

Feb 18, 2025
CVE-2024-56901
8.8

This CSRF vulnerability in Geovision GV-ASWeb allows attackers to create administrator accounts without authentication by tricking authenticated users...

Feb 3, 2025
CVE-2024-13707
8.8

This CSRF vulnerability in WP Image Uploader plugin allows unauthenticated attackers to delete arbitrary files on WordPress sites by tricking administ...

Jan 30, 2025
CVE-2024-13720
8.8

The WP Image Uploader WordPress plugin allows unauthenticated attackers to delete arbitrary files on the server due to insufficient file path validati...

Jan 30, 2025
CVE-2024-54851
8.8

Teedy versions up to 1.12 lack CSRF protection, allowing attackers to trick authenticated users into performing unintended actions. This affects all T...

Jan 29, 2025
CVE-2024-48418
8.8

This vulnerability allows authenticated attackers to execute arbitrary shell commands on Edimax AC1200 routers by injecting special characters into DD...

Jan 27, 2025
CVE-2024-11641
8.8

This CSRF vulnerability in the VikBooking WordPress plugin allows attackers to trick administrators into performing actions that change plugin access ...

Jan 26, 2025
CVE-2025-24398
8.8

The Jenkins Bitbucket Server Integration Plugin has a CSRF bypass vulnerability that allows attackers to craft malicious URLs that circumvent CSRF pro...

Jan 22, 2025
CVE-2025-23530
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Custom Post Type Lockdown plugin allows attackers to trick authenticated administra...

Jan 16, 2025
CVE-2025-23532
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the Regios MyAnime Widget WordPress plugin allows attackers to trick authenticated administrators...

Jan 16, 2025
CVE-2024-50858
8.8

GestioIP v3.5.7 contains CSRF vulnerabilities in multiple endpoints that allow attackers to trick authenticated administrators into performing unautho...

Jan 14, 2025
CVE-2024-13284
8.8

This CSRF vulnerability in Drupal Gutenberg allows attackers to trick authenticated users into performing unintended actions on the Drupal site. It af...

Jan 9, 2025
CVE-2024-13244
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows attackers to trick authenticated administrators into performing unaut...

Jan 9, 2025
CVE-2024-13250
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in Drupal Symfony Mailer Lite allows attackers to trick authenticated users into performing unint...

Jan 9, 2025
CVE-2024-12322
8.8

This CSRF vulnerability in ThePerfectWedding.nl Widget plugin for WordPress allows attackers to inject malicious scripts into the plugin's configurati...

Jan 7, 2025
CVE-2024-39623
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the ListingPro WordPress theme allows attackers to bypass authentication and potentially take ove...

Jan 2, 2025
CVE-2024-56203
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the Wayne Audio Player WordPress plugin allows attackers to trick authenticated administrators in...

Dec 31, 2024
CVE-2024-56206
8.8

This CSRF vulnerability in the Amarjeet Amar gap-hub-user-role WordPress plugin allows attackers to bypass authentication by tricking authenticated us...

Dec 31, 2024
CVE-2024-56310
8.8

REDCap versions through 14.9.6 have a CSRF vulnerability in Project Dashboards that allows attackers to force user logout by tricking users into click...

Dec 22, 2024
CVE-2024-37758
8.8

This vulnerability allows authenticated attackers to escalate privileges in Digiteam v4.21.0.0 by exploiting improper access control in the /RoleMenuM...

Dec 20, 2024
CVE-2024-56116
8.8

A Cross-Site Request Forgery vulnerability in Amiro.CMS allows attackers to create administrator accounts without authorization. This affects all Amir...

Dec 18, 2024
CVE-2024-55088
8.8

GetSimple CMS CE 3.3.19 contains a Server-Side Request Forgery (SSRF) vulnerability in its backend plugin module. This allows authenticated attackers ...

Dec 18, 2024
CVE-2024-12293
8.8

The User Role Editor WordPress plugin has a CSRF vulnerability that allows unauthenticated attackers to modify user roles, including granting administ...

Dec 17, 2024
CVE-2024-54248
8.8

This CSRF vulnerability in the eewee admin custom WordPress plugin allows attackers to trick authenticated administrators into performing unintended a...

Dec 13, 2024
CVE-2024-11689
8.8

The HQ Rental Software WordPress plugin has a CSRF vulnerability that allows unauthenticated attackers to trick administrators into performing actions...

Dec 12, 2024
CVE-2020-28398
8.8

This CSRF vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to trick authenticated users into executing unauthorized configuration chang...

Dec 10, 2024
CVE-2024-53472
8.8

WeGIA v3.2.0 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to trick authenticated users into performing unintended ...

Dec 5, 2024
CVE-2024-39163
8.8

This CSRF vulnerability in pyspider allows attackers to trick authenticated users into performing unintended actions via malicious web requests. It af...

Dec 4, 2024
CVE-2024-11415
8.8

The WP-Orphanage Extended WordPress plugin has a CSRF vulnerability that allows unauthenticated attackers to escalate privileges for all orphan accoun...

Nov 23, 2024
CVE-2024-52002
8.8

This CSRF vulnerability in Combodo iTop allows attackers to trick authenticated users into performing unintended actions by visiting malicious web pag...

Nov 8, 2024
CVE-2024-9990
8.8

This CSRF vulnerability in the WordPress Crypto plugin allows unauthenticated attackers to log in as any existing user, including administrators, by t...

Oct 29, 2024
CVE-2022-30357
8.8

OvalEdge versions 5.2.8.0 and earlier contain an authentication-required CSRF vulnerability that allows attackers to take over user accounts by manipu...

Oct 25, 2024
CVE-2024-9598
8.8

This CSRF vulnerability in the AMP for WordPress plugin allows attackers to steal logged-in users' cookies by tricking administrators into clicking ma...

Oct 25, 2024
CVE-2024-26271
8.8

This CSRF vulnerability in Liferay Portal/DXP allows attackers to trick authenticated users into performing unauthorized actions by clicking malicious...

Oct 22, 2024
CVE-2024-26273
8.8

A CSRF vulnerability in Liferay Portal and DXP allows attackers to trick authenticated administrators into performing unauthorized actions. Attackers ...

Oct 22, 2024
CVE-2020-36836
8.8

The WP Fastest Cache WordPress plugin allows authenticated users with minimal permissions to delete arbitrary files from the server due to missing cap...

Oct 16, 2024
CVE-2024-8458
8.8

PLANET Technology switches have a CSRF vulnerability in their web interface that allows unauthenticated remote attackers to trick authenticated users ...

Sep 30, 2024
CVE-2024-8795
8.8

The BA Book Everything WordPress plugin has a CSRF vulnerability that allows unauthenticated attackers to trick administrators into clicking malicious...

Sep 24, 2024
CVE-2024-46086
8.8

This CSRF vulnerability in FrogCMS allows attackers to trick authenticated administrators into performing unauthorized file deletion actions. Attacker...

Sep 18, 2024
CVE-2024-46085
8.8

FrogCMS V0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the file manager rename functionality. This allows attackers to trick aut...

Sep 17, 2024
CVE-2024-8490
8.8

This CSRF vulnerability in the PropertyHive WordPress plugin allows unauthenticated attackers to change administrator account details (name, email, pa...

Sep 17, 2024

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,357 CVEs classified as CWE-352, with 63 rated critical and 1,280 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.6.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free