CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,365
Total CVEs
63
Critical
1,288
High
6.7
Avg CVSS

Yearly Trend

2026
121
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 52
2 Idccms 25
3 Ibm 23
4 Dedecms 14
5 Jfinalcms Project 10
6 Cisco 10
7 Flycms Project 9
8 Enalean 8
9 Tipsandtricks Hq 8
10 Pligg 8

All Cross-Site Request Forgery (CSRF) CVEs (2,365)

CVE-2024-36550
8.8

This CSRF vulnerability in idccms V1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted reques...

Jun 4, 2024
CVE-2024-34007
8.8

This CSRF vulnerability in MFA logout allows attackers to forcibly log out authenticated users by tricking them into clicking malicious links. It affe...

May 31, 2024
CVE-2024-4535
8.8

The KKProgressbar2 Free WordPress plugin versions through 1.1.4.2 lack CSRF protection on certain endpoints, allowing attackers to trick authenticated...

May 27, 2024
CVE-2024-35552
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted reques...

May 22, 2024
CVE-2024-35556
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted reques...

May 22, 2024
CVE-2024-35558
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via malicious requ...

May 22, 2024
CVE-2024-36076
8.8

This Cross-Site WebSocket Hijacking vulnerability in SysReptor allows attackers to hijack WebSocket connections when a logged-in user visits a malicio...

May 19, 2024
CVE-2024-3643
8.8

This vulnerability in the Newsletter Popup WordPress plugin allows attackers to trick logged-in administrators into deleting newsletter lists via Cros...

May 16, 2024
CVE-2024-35108
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions via crafted reques...

May 15, 2024
CVE-2024-35010
8.8

This CSRF vulnerability in idccms v1.35 allows attackers to trick authenticated administrators into performing unauthorized actions, specifically dele...

May 14, 2024
CVE-2024-3940
8.8

This vulnerability allows attackers to trick logged-in WordPress administrators into unknowingly changing the reCAPTCHA Jetpack plugin settings via a ...

May 14, 2024
CVE-2024-3474
8.8

The Wow Skype Buttons WordPress plugin before version 4.0.4 lacks CSRF protection on some bulk actions, allowing attackers to trick logged-in administ...

May 2, 2024
CVE-2024-3476
8.8

The Side Menu Lite WordPress plugin before version 4.2.1 lacks CSRF protection on certain bulk actions, allowing attackers to trick logged-in administ...

May 2, 2024
CVE-2024-31424
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the WordPress 'Login with phone number' plugin allows attackers to trick authenticated adminis...

Apr 15, 2024
CVE-2024-25572
8.8

This CSRF vulnerability in Ninja Forms WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions on t...

Apr 11, 2024
CVE-2024-2196
8.8

This CSRF vulnerability in aimhubio/aim allows attackers to trick authenticated users into executing unauthorized actions like deleting runs, updating...

Apr 10, 2024
CVE-2024-2125
8.8

This CSRF vulnerability in the EnvíaloSimple WordPress plugin allows unauthenticated attackers to upload malicious files by tricking administrators i...

Apr 9, 2024
CVE-2024-30965
8.8

DedeCMS v5.7 contains a CSRF vulnerability in the member_scores.php component that allows attackers to trick authenticated administrators into perform...

Apr 2, 2024
CVE-2024-1522
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary OS commands on a v...

Mar 30, 2024
CVE-2024-1962
8.8

This CSRF vulnerability in CM Download Manager WordPress plugin allows attackers to trick authenticated administrators into unknowingly modifying down...

Mar 25, 2024
CVE-2024-1538
8.8

This CSRF vulnerability in the WordPress File Manager plugin allows unauthenticated attackers to trick administrators into executing malicious JavaScr...

Mar 21, 2024
CVE-2024-0856
8.8

This vulnerability in the Appointment Booking Calendar WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against ...

Mar 20, 2024
CVE-2024-0779
8.8

The Enjoy Social Feed WordPress plugin through version 6.2.2 lacks proper authorization and CSRF protection on admin_init functions, allowing unauthen...

Mar 18, 2024
CVE-2024-0858
8.8

The Innovs HR WordPress plugin through version 1.0.3.4 lacks Cross-Site Request Forgery (CSRF) protection on certain endpoints, allowing attackers to ...

Mar 18, 2024
CVE-2023-51474
8.8

This CSRF vulnerability in the TerraClassifieds WordPress plugin allows attackers to trick authenticated users into performing unauthorized actions. I...

Mar 16, 2024
CVE-2024-28673
8.8

DedeCMS v5.7 contains a CSRF vulnerability in the mychannel_edit.php component that allows attackers to trick authenticated administrators into perfor...

Mar 13, 2024
CVE-2024-28675
8.8

DedeCMS v5.7 contains a CSRF vulnerability in the /dede/diy_edit.php endpoint that allows attackers to trick authenticated administrators into perform...

Mar 13, 2024
CVE-2024-28665
8.8

DedeCMS v5.7 contains a Cross-Site Request Forgery (CSRF) vulnerability in the article_add.php component that allows attackers to trick authenticated ...

Mar 13, 2024
CVE-2024-28431
8.8

DedeCMS v5.7 contains a CSRF vulnerability in the catalog_del.php component that allows attackers to trick authenticated administrators into performin...

Mar 13, 2024
CVE-2024-0203
8.8

The Digits WordPress plugin has a CSRF vulnerability that allows attackers to change user roles to administrator by tricking an admin into clicking a ...

Mar 7, 2024
CVE-2024-27689
8.8

Stupid Simple CMS v1.2.4 contains a CSRF vulnerability in the /update-article.php endpoint that allows attackers to trick authenticated administrators...

Mar 1, 2024
CVE-2024-22939
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in FlyCms v1.0 allows attackers to trick authenticated users into performing unintended actions, ...

Feb 29, 2024
CVE-2024-23910
8.8

A cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and repeaters allows remote unauthenticated attackers to trick admini...

Feb 28, 2024
CVE-2023-52047
8.8

This CSRF vulnerability in Dedecms v5.7.112 allows attackers to trick authenticated administrators into performing unauthorized actions via the file m...

Feb 28, 2024
CVE-2023-36237
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in Bagisto e-commerce platform allows attackers to trick authenticated users into executing malic...

Feb 26, 2024
CVE-2024-1889
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in SMA Cluster Controller version 01.05.01.R. An attacker can trick authenticated...

Feb 26, 2024
CVE-2024-26350
8.8

Flusity-CMS v2.33 contains a Cross-Site Request Forgery vulnerability in the contact form settings update component. This allows attackers to trick au...

Feb 22, 2024
CVE-2024-26352
8.8

Flusity-CMS v2.33 contains a CSRF vulnerability in the /core/tools/add_places.php component that allows attackers to trick authenticated administrator...

Feb 22, 2024
CVE-2021-29050
8.8

This CSRF vulnerability in Liferay Portal allows attackers to trick authenticated users into accepting terms of use without their consent by visiting ...

Feb 20, 2024
CVE-2024-25417
8.8

Flusity-CMS v2.33 contains a CSRF vulnerability in the translation management component that allows attackers to trick authenticated administrators in...

Feb 11, 2024
CVE-2024-25419
8.8

Flusity-CMS v2.33 contains a CSRF vulnerability in the update_menu.php component that allows attackers to trick authenticated administrators into perf...

Feb 11, 2024
CVE-2023-47020
8.8

This vulnerability in NCR Terminal Handler v1.5.1 allows attackers to chain multiple CSRF attacks to create new user accounts and add them to administ...

Feb 8, 2024
CVE-2024-24468
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in flusity-CMS v2.33 allows remote attackers to execute arbitrary code via the add_customblock.php e...

Feb 5, 2024
CVE-2024-24524
8.8

This CSRF vulnerability in flusity-CMS v2.33 allows attackers to trick authenticated administrators into executing arbitrary code by visiting maliciou...

Feb 2, 2024
CVE-2024-22140
8.8

This CSRF vulnerability in Profile Builder Pro WordPress plugin allows attackers to trick authenticated administrators into performing unintended acti...

Jan 31, 2024
CVE-2023-6390
8.8

This vulnerability in the WordPress Users plugin allows attackers to trick logged-in administrators into changing plugin settings without their consen...

Jan 29, 2024
CVE-2023-6946
8.8

This vulnerability in the Autotitle for WordPress plugin allows attackers to trick logged-in administrators into changing plugin settings without thei...

Jan 29, 2024
CVE-2023-47024
8.8

This CSRF vulnerability in NCR Terminal Handler v1.5.1 allows attackers to perform one-click account takeover by exploiting weak security controls in ...

Jan 20, 2024
CVE-2024-22601
8.8

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the /system/score/scorerule_save endpoint. This allows attackers to trick au...

Jan 18, 2024
CVE-2024-22817
8.8

FlyCms v1.0 contains a CSRF vulnerability in the email configuration update endpoint that allows attackers to trick authenticated administrators into ...

Jan 18, 2024

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,365 CVEs classified as CWE-352, with 63 rated critical and 1,288 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free