CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,370
Total CVEs
63
Critical
1,293
High
6.7
Avg CVSS

Yearly Trend

2026
121
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 52
2 Idccms 25
3 Ibm 23
4 Dedecms 14
5 Cisco 11
6 Jfinalcms Project 10
7 Flycms Project 9
8 Enalean 8
9 Tipsandtricks Hq 8
10 Pligg 8

All Cross-Site Request Forgery (CSRF) CVEs (2,370)

CVE-2024-22819
8.8

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the email template update endpoint. This allows attackers to trick authentic...

Jan 18, 2024
CVE-2024-22699
8.8

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the group update functionality. This allows attackers to trick authenticated...

Jan 18, 2024
CVE-2024-22568
8.8

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the score deletion endpoint (/system/score/del). This allows attackers to tr...

Jan 18, 2024
CVE-2024-22592
8.8

FlyCms v1.0 contains a CSRF vulnerability in the user group update endpoint that allows attackers to trick authenticated administrators into performin...

Jan 18, 2024
CVE-2024-22715
8.8

Stupid Simple CMS versions up to 1.2.4 contain a Cross-Site Request Forgery (CSRF) vulnerability in the admin-edit.php component. This allows attacker...

Jan 17, 2024
CVE-2023-52072
8.8

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the /system/site/userconfig_updagte component. This allows attackers to tric...

Jan 8, 2024
CVE-2023-52074
8.8

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the web configuration update component. This allows attackers to trick authe...

Jan 8, 2024
CVE-2023-6532
8.8

This vulnerability in the WP Blogs' Planetarium WordPress plugin allows attackers to trick logged-in administrators into changing plugin settings with...

Jan 8, 2024
CVE-2023-6845
8.8

The CommentTweets WordPress plugin through version 0.6 lacks CSRF protection on certain endpoints, allowing attackers to trick logged-in administrator...

Jan 8, 2024
CVE-2023-5961
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in ioLogik E1200 Series firmware allows attackers to trick authenticated users into performing unint...

Dec 23, 2023
CVE-2023-5882
8.8

This vulnerability in WordPress export plugins allows attackers to bypass CSRF protection and trick logged-in users into performing unauthorized actio...

Dec 18, 2023
CVE-2023-50778
8.8

A CSRF vulnerability in Jenkins PaaSLane Estimate Plugin allows attackers to trick authenticated users into making unauthorized requests to attacker-c...

Dec 13, 2023
CVE-2023-50766
8.8

This CSRF vulnerability in Jenkins Nexus Platform Plugin allows attackers to trick authenticated users into making unintended HTTP requests to attacke...

Dec 13, 2023
CVE-2023-50768
8.8

This CSRF vulnerability in Jenkins Nexus Platform Plugin allows attackers to trick authenticated users into connecting Jenkins to malicious HTTP serve...

Dec 13, 2023
CVE-2023-47322
8.8

This CSRF vulnerability in Silverpeas Core allows attackers to escalate privileges by tricking authenticated administrators into visiting malicious UR...

Dec 13, 2023
CVE-2023-47326
8.8

Silverpeas Core 6.3.1 has a CSRF vulnerability in its Domain SQL Create function that allows attackers to trick authenticated users into executing una...

Dec 13, 2023
CVE-2023-49378
8.8

JFinalCMS v5.0.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the /admin/form/save endpoint that allows attackers to trick authentica...

Dec 5, 2023
CVE-2023-49380
8.8

JFinalCMS v5.0.0 contains a CSRF vulnerability in the friend link deletion endpoint (/admin/friend_link/delete) that allows attackers to trick authent...

Dec 5, 2023
CVE-2023-49382
8.8

JFinalCMS v5.0.0 contains a CSRF vulnerability in the custom table deletion endpoint (/admin/div/delete). This allows attackers to trick authenticated...

Dec 5, 2023
CVE-2023-49395
8.8

JFinalCMS v5.0.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the column management modification endpoint (/admin/category/update). T...

Dec 5, 2023
CVE-2023-49397
8.8

JFinalCMS v5.0.0 contains a CSRF vulnerability in the category status update endpoint (/admin/category/updateStatus) that allows attackers to trick au...

Dec 5, 2023
CVE-2023-49446
8.8

JFinalCMS v5.0.0 contains a CSRF vulnerability in the navigation management area that allows attackers to trick authenticated administrators into perf...

Dec 5, 2023
CVE-2023-49448
8.8

JFinalCMS v5.0.0 contains a CSRF vulnerability in the navigation management delete endpoint. This allows attackers to trick authenticated administrato...

Dec 5, 2023
CVE-2023-49372
8.8

JFinalCMS v5.0.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the slide management endpoint (/admin/slide/save). This allows attacker...

Dec 5, 2023
CVE-2023-49374
8.8

JFinalCMS v5.0.0 contains a CSRF vulnerability in the rotation image editing functionality at /admin/slide/update. This allows attackers to trick auth...

Dec 5, 2023
CVE-2023-49376
8.8

JFinalCMS v5.0.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tag deletion endpoint (/admin/tag/delete). This allows attackers to...

Dec 5, 2023
CVE-2023-24048
8.8

This CSRF vulnerability in Connectize AC21000 G6 routers allows attackers to change the administrator password via a crafted GET request to /man_passw...

Dec 4, 2023
CVE-2023-48913
8.8

Dreamer CMS v4.1.3 contains a CSRF vulnerability in the article deletion function that allows attackers to trick authenticated administrators into per...

Nov 30, 2023
CVE-2023-47781
8.8

This CSRF vulnerability in Thrive Theme Builder allows attackers to trick authenticated WordPress administrators into performing unintended actions. I...

Nov 22, 2023
CVE-2023-2440
8.8

The UserPro WordPress plugin up to version 5.1.1 has a Cross-Site Request Forgery vulnerability that allows unauthenticated attackers to trick adminis...

Nov 22, 2023
CVE-2023-4824
8.8

This vulnerability in the WooHoo Newspaper Magazine WordPress theme allows attackers to trick logged-in administrators into changing theme settings wi...

Nov 20, 2023
CVE-2023-48293
8.8

This CSRF vulnerability in XWiki Admin Tools allows attackers to execute arbitrary database queries when an admin user views malicious content. It aff...

Nov 20, 2023
CVE-2023-6022
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in Prefect allows attackers to trick authenticated users into performing unintended actions on th...

Nov 16, 2023
CVE-2023-48058
8.8

Dreamer CMS v4.1.3 contains a CSRF vulnerability in the task management execution endpoint (/admin/task/run) that allows attackers to trick authentica...

Nov 13, 2023
CVE-2023-35041
8.8

This vulnerability allows attackers to trick authenticated WordPress administrators into performing unintended actions via Cross-Site Request Forgery ...

Nov 13, 2023
CVE-2023-26516
8.8

This CSRF vulnerability in the WPIndeed Debug Assistant WordPress plugin allows attackers to trick authenticated administrators into performing uninte...

Nov 13, 2023
CVE-2023-29426
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Spreadshop plugin allows attackers to trick authenticated administrators into pe...

Nov 10, 2023
CVE-2023-29440
8.8

This CSRF vulnerability in the Simple Job Board WordPress plugin allows attackers to trick authenticated administrators into performing unintended act...

Nov 10, 2023
CVE-2023-31077
8.8

This CSRF vulnerability in the Export WP Page to Static HTML/CSS WordPress plugin allows attackers to trick authenticated administrators into performi...

Nov 10, 2023
CVE-2023-31086
8.8

This CSRF vulnerability in the Simple Giveaways WordPress plugin allows attackers to trick authenticated administrators into performing unintended act...

Nov 9, 2023
CVE-2023-31093
8.8

This CSRF vulnerability in the Chronosly Events Calendar WordPress plugin allows attackers to trick authenticated administrators into performing unint...

Nov 9, 2023
CVE-2023-32092
8.8

This CSRF vulnerability in the PeepSo WordPress plugin allows attackers to trick authenticated users into performing unintended actions on their behal...

Nov 9, 2023
CVE-2023-32125
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Daniel Powney Multi Rating WordPress plugin allows attackers to trick authenticated admini...

Nov 9, 2023
CVE-2023-32501
8.8

This CSRF vulnerability in VikBooking Hotel Booking Engine & PMS plugin allows attackers to trick authenticated WordPress administrators into performi...

Nov 9, 2023
CVE-2023-32579
8.8

This CSRF vulnerability in the WordPress Forget About Shortcode Buttons plugin allows attackers to trick authenticated administrators into performing ...

Nov 9, 2023
CVE-2023-32592
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Sunny Search WordPress plugin allows attackers to trick authenticated administrators into ...

Nov 9, 2023
CVE-2023-32594
8.8

This CSRF vulnerability in the WordPress Hyphenator plugin allows attackers to trick authenticated administrators into performing unintended actions. ...

Nov 9, 2023
CVE-2023-32739
8.8

This CSRF vulnerability in the WordPress WP Custom Cursors plugin allows attackers to trick authenticated administrators into performing unintended ac...

Nov 9, 2023
CVE-2023-32745
8.8

This CSRF vulnerability in the WooCommerce AutomateWoo plugin allows attackers to trick authenticated administrators into performing unintended action...

Nov 9, 2023
CVE-2023-34024
8.8

This CSRF vulnerability in the WP Full Auto Tags Manager WordPress plugin allows attackers to trick authenticated administrators into performing unint...

Nov 9, 2023

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,370 CVEs classified as CWE-352, with 63 rated critical and 1,293 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free