CWE-352: Cross-Site Request Forgery (CSRF)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Yearly Trend
Top Affected Vendors
All Cross-Site Request Forgery (CSRF) CVEs (2,364)
The Stream plugin for WordPress has a Cross-Site Request Forgery vulnerability that allows unauthenticated attackers to trick administrators into perf...
Sep 13, 2024This CSRF vulnerability in SkySystem Arfa-CMS allows attackers to create new administrator accounts by tricking authenticated admin users into visitin...
Aug 27, 2024This CSRF vulnerability in Pligg CMS allows attackers to trick authenticated administrators into performing unauthorized actions by adding domains to ...
Aug 20, 2024Pligg CMS v2.0.2 contains a Cross-Site Request Forgery (CSRF) vulnerability in the admin page editor. This allows attackers to trick authenticated adm...
Aug 20, 2024Pligg CMS v2.0.2 contains a CSRF vulnerability in the admin backup functionality. Attackers can trick authenticated administrators into performing una...
Aug 20, 2024This CSRF vulnerability in Pligg CMS v2.0.2 allows attackers to trick authenticated administrators into performing unauthorized backup operations via ...
Aug 20, 2024This CSRF vulnerability in Pligg CMS allows attackers to trick authenticated administrators into unknowingly installing malicious widgets. Attackers c...
Aug 20, 2024This CSRF vulnerability in Pligg CMS v2.0.2 allows attackers to trick authenticated administrators into performing unauthorized configuration changes ...
Aug 20, 2024Pligg CMS v2.0.2 contains a CSRF vulnerability in the admin editor that allows attackers to trick authenticated administrators into performing unautho...
Aug 20, 2024This CSRF vulnerability in Pligg CMS v2.0.2 allows attackers to trick authenticated administrators into performing unauthorized backup clearing action...
Aug 20, 2024A Cross-Site Request Forgery vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated administrators into performing u...
Aug 20, 2024A Cross-Site Request Forgery vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated users into performing unauthoriz...
Aug 20, 2024A Cross-Site Request Forgery (CSRF) vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated users into performing una...
Aug 20, 2024This CSRF vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated users into performing unauthorized actions, specifi...
Aug 20, 2024A Cross-Site Request Forgery vulnerability in Warehouse Inventory System v2.0 allows attackers to trick authenticated users into performing unauthoriz...
Aug 20, 2024This CSRF vulnerability in Hotel Management System's admin_room_added.php component allows attackers to trick authenticated administrators into perfor...
Aug 20, 2024A Cross-Site Request Forgery vulnerability in the Hotel Management System's admin_room_removed.php component allows attackers to trick authenticated a...
Aug 20, 2024FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the layout addition functionality at /admin/?/layout/add. This allows att...
Aug 12, 2024FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the snippet deletion functionality. Attackers can trick authenticated adm...
Aug 12, 2024FrogCMS v0.9.5 contains a CSRF vulnerability in the layout deletion endpoint that allows attackers to trick authenticated administrators into performi...
Aug 12, 2024FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the layout editing functionality at /admin/?/layout/edit/1. This allows a...
Aug 12, 2024FrogCMS v0.9.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the page edit functionality at /admin/?/page/edit/10. This allows attacke...
Aug 12, 2024This CSRF vulnerability in Kashipara Live Membership System v1.0 allows attackers to trick authenticated administrators into performing unauthorized a...
Aug 12, 2024The Light Poll WordPress plugin through version 1.0.0 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to t...
Aug 6, 2024This CSRF vulnerability in the Superfly Responsive Menu WordPress plugin allows unauthenticated attackers to delete arbitrary files on affected websit...
Aug 2, 2024This vulnerability in parisneo/lollms-webui allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against binding management endpoints...
Aug 1, 2024This CSRF vulnerability in ELECOM wireless LAN routers allows attackers to trick authenticated administrators into performing unauthorized configurati...
Aug 1, 2024This vulnerability in the PZ Frontend Manager WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against logged-in...
Jul 22, 2024This CSRF vulnerability in Nepstech Wifi Router xpon (terminal) allows attackers to trick authenticated users into unknowingly changing the admin pass...
Jul 17, 2024This CSRF vulnerability in the wp-cart-for-digital-products WordPress plugin allows attackers to trick logged-in administrators into performing unauth...
Jul 15, 2024The SULly WordPress plugin before version 4.3.1 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to trick a...
Jul 13, 2024The wp-eMember WordPress plugin before version 10.6.6 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to t...
Jul 13, 2024This vulnerability in the ContentLock WordPress plugin allows attackers to trick logged-in administrators into deleting groups or emails without their...
Jul 12, 2024This CSRF vulnerability in the ContentLock WordPress plugin allows attackers to trick authenticated administrators into unknowingly changing plugin se...
Jul 12, 2024This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized database backup operations...
Jul 10, 2024This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically data...
Jul 10, 2024CVE-2024-40334 is a Cross-Site Request Forgery (CSRF) vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into p...
Jul 10, 2024This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...
Jul 9, 2024This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...
Jul 9, 2024This CSRF vulnerability in the Generate PDF using Contact Form 7 WordPress plugin allows unauthenticated attackers to upload arbitrary files to affect...
Jul 9, 2024CVE-2024-39022 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performi...
Jul 5, 2024This Cross-Site Request Forgery (CSRF) vulnerability in the Nested Pages WordPress plugin allows unauthenticated attackers to execute arbitrary PHP fi...
Jul 4, 2024The WPQA Builder WordPress plugin before version 6.1.1 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to ...
Jul 3, 2024CVE-2024-39158 is a Cross-Site Request Forgery vulnerability in idccms v1.35 that allows attackers to trick authenticated administrators into performi...
Jun 27, 2024This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...
Jun 27, 2024This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in XenForo forum software versions before 2.2.16. Attackers can trick authenticat...
Jun 16, 2024A Cross-Site Request Forgery (CSRF) vulnerability in AutoGPT v0.5.0 allows attackers to execute arbitrary commands on the AutoGPT server by tricking u...
Jun 6, 2024This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions by visiting malici...
Jun 5, 2024This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via the admin/type...
Jun 5, 2024This CSRF vulnerability in idccms V1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically dele...
Jun 4, 2024About Cross-Site Request Forgery (CSRF) (CWE-352)
The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Our database tracks 2,364 CVEs classified as CWE-352, with 63 rated critical and 1,287 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.
External reference: View CWE-352 on MITRE CWE →
Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities
Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.
Start Monitoring Free