CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,364
Total CVEs
63
Critical
1,287
High
6.7
Avg CVSS

Yearly Trend

2026
121
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 52
2 Idccms 25
3 Ibm 23
4 Dedecms 14
5 Jfinalcms Project 10
6 Cisco 10
7 Flycms Project 9
8 Enalean 8
9 Tipsandtricks Hq 8
10 Pligg 8

All Cross-Site Request Forgery (CSRF) CVEs (2,364)

CVE-2024-7423
8.8

The Stream plugin for WordPress has a Cross-Site Request Forgery vulnerability that allows unauthenticated attackers to trick administrators into perf...

Sep 13, 2024
CVE-2024-45264
8.8

This CSRF vulnerability in SkySystem Arfa-CMS allows attackers to create new administrator accounts by tricking authenticated admin users into visitin...

Aug 27, 2024
CVE-2024-42612
8.8

This CSRF vulnerability in Pligg CMS allows attackers to trick authenticated administrators into performing unauthorized actions by adding domains to ...

Aug 20, 2024
CVE-2024-42605
8.8

Pligg CMS v2.0.2 contains a Cross-Site Request Forgery (CSRF) vulnerability in the admin page editor. This allows attackers to trick authenticated adm...

Aug 20, 2024
CVE-2024-42607
8.8

Pligg CMS v2.0.2 contains a CSRF vulnerability in the admin backup functionality. Attackers can trick authenticated administrators into performing una...

Aug 20, 2024
CVE-2024-42610
8.8

This CSRF vulnerability in Pligg CMS v2.0.2 allows attackers to trick authenticated administrators into performing unauthorized backup operations via ...

Aug 20, 2024
CVE-2024-42613
8.8

This CSRF vulnerability in Pligg CMS allows attackers to trick authenticated administrators into unknowingly installing malicious widgets. Attackers c...

Aug 20, 2024
CVE-2024-42617
8.8

This CSRF vulnerability in Pligg CMS v2.0.2 allows attackers to trick authenticated administrators into performing unauthorized configuration changes ...

Aug 20, 2024
CVE-2024-42621
8.8

Pligg CMS v2.0.2 contains a CSRF vulnerability in the admin editor that allows attackers to trick authenticated administrators into performing unautho...

Aug 20, 2024
CVE-2024-42603
8.8

This CSRF vulnerability in Pligg CMS v2.0.2 allows attackers to trick authenticated administrators into performing unauthorized backup clearing action...

Aug 20, 2024
CVE-2024-42583
8.8

A Cross-Site Request Forgery vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated administrators into performing u...

Aug 20, 2024
CVE-2024-42585
8.8

A Cross-Site Request Forgery vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated users into performing unauthoriz...

Aug 20, 2024
CVE-2024-42577
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated users into performing una...

Aug 20, 2024
CVE-2024-42579
8.8

This CSRF vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated users into performing unauthorized actions, specifi...

Aug 20, 2024
CVE-2024-42581
8.8

A Cross-Site Request Forgery vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated users into performing unauthoriz...

Aug 20, 2024
CVE-2024-42553
8.8

This CSRF vulnerability in Hotel Management System's admin_room_added.php component allows attackers to trick authenticated administrators into perfor...

Aug 20, 2024
CVE-2024-42555
8.8

A Cross-Site Request Forgery vulnerability in the Hotel Management System's admin_room_removed.php component allows attackers to trick authenticated a...

Aug 20, 2024
CVE-2024-42625
8.8

FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the layout addition functionality at /admin/?/layout/add. This allows att...

Aug 12, 2024
CVE-2024-42627
8.8

FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the snippet deletion functionality. Attackers can trick authenticated adm...

Aug 12, 2024
CVE-2024-42623
8.8

FrogCMS v0.9.5 contains a CSRF vulnerability in the layout deletion endpoint that allows attackers to trick authenticated administrators into performi...

Aug 12, 2024
CVE-2024-42631
8.8

FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the layout editing functionality at /admin/?/layout/edit/1. This allows a...

Aug 12, 2024
CVE-2024-42629
8.8

FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the page edit functionality at /admin/?/page/edit/10. This allows attacke...

Aug 12, 2024
CVE-2024-40488
8.8

This CSRF vulnerability in Kashipara Live Membership System v1.0 allows attackers to trick authenticated administrators into performing unauthorized a...

Aug 12, 2024
CVE-2024-6720
8.8

The Light Poll WordPress plugin through version 1.0.0 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to t...

Aug 6, 2024
CVE-2024-3238
8.8

This CSRF vulnerability in the Superfly Responsive Menu WordPress plugin allows unauthenticated attackers to delete arbitrary files on affected websit...

Aug 2, 2024
CVE-2024-6040
8.8

This vulnerability in parisneo/lollms-webui allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against binding management endpoints...

Aug 1, 2024
CVE-2024-40883
8.8

This CSRF vulnerability in ELECOM wireless LAN routers allows attackers to trick authenticated administrators into performing unauthorized configurati...

Aug 1, 2024
CVE-2024-6244
8.8

This vulnerability in the PZ Frontend Manager WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against logged-in...

Jul 22, 2024
CVE-2024-40119
8.8

This CSRF vulnerability in Nepstech Wifi Router xpon (terminal) allows attackers to trick authenticated users into unknowingly changing the admin pass...

Jul 17, 2024
CVE-2024-6075
8.8

This CSRF vulnerability in the wp-cart-for-digital-products WordPress plugin allows attackers to trick logged-in administrators into performing unauth...

Jul 15, 2024
CVE-2024-5034
8.8

The SULly WordPress plugin before version 4.3.1 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to trick a...

Jul 13, 2024
CVE-2024-5076
8.8

The wp-eMember WordPress plugin before version 10.6.6 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to t...

Jul 13, 2024
CVE-2024-6024
8.8

This vulnerability in the ContentLock WordPress plugin allows attackers to trick logged-in administrators into deleting groups or emails without their...

Jul 12, 2024
CVE-2024-6022
8.8

This CSRF vulnerability in the ContentLock WordPress plugin allows attackers to trick authenticated administrators into unknowingly changing plugin se...

Jul 12, 2024
CVE-2024-40331
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized database backup operations...

Jul 10, 2024
CVE-2024-40329
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically data...

Jul 10, 2024
CVE-2024-40334
8.8

CVE-2024-40334 is a Cross-Site Request Forgery (CSRF) vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into p...

Jul 10, 2024
CVE-2024-40034
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...

Jul 9, 2024
CVE-2024-40039
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...

Jul 9, 2024
CVE-2024-6316
8.8

This CSRF vulnerability in the Generate PDF using Contact Form 7 WordPress plugin allows unauthenticated attackers to upload arbitrary files to affect...

Jul 9, 2024
CVE-2024-39022
8.8

CVE-2024-39022 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performi...

Jul 5, 2024
CVE-2024-5943
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Nested Pages WordPress plugin allows unauthenticated attackers to execute arbitrary PHP fi...

Jul 4, 2024
CVE-2024-2376
8.8

The WPQA Builder WordPress plugin before version 6.1.1 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to ...

Jul 3, 2024
CVE-2024-39158
8.8

CVE-2024-39158 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performi...

Jun 27, 2024
CVE-2024-39154
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...

Jun 27, 2024
CVE-2024-38457
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in XenForo forum software versions before 2.2.16. Attackers can trick authenticat...

Jun 16, 2024
CVE-2024-1879
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in AutoGPT v0.5.0 allows attackers to execute arbitrary commands on the AutoGPT server by tricking u...

Jun 6, 2024
CVE-2024-36667
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...

Jun 5, 2024
CVE-2024-36669
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via the admin/type...

Jun 5, 2024
CVE-2024-36548
8.8

This CSRF vulnerability in idccms V1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically dele...

Jun 4, 2024

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,364 CVEs classified as CWE-352, with 63 rated critical and 1,287 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free