CWE-352: Cross-Site Request Forgery (CSRF)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

2,376
Total CVEs
63
Critical
1,299
High
6.7
Avg CVSS

Yearly Trend

2026
121
2025
1,302
2024
529
2023
186
2022
95

Top Affected Vendors

1 Jenkins 52
2 Idccms 25
3 Ibm 23
4 Dedecms 14
5 Cisco 11
6 Jfinalcms Project 10
7 Flycms Project 9
8 Pligg 8
9 Enalean 8
10 Tipsandtricks Hq 8

All Cross-Site Request Forgery (CSRF) CVEs (2,376)

CVE-2023-34031
8.8

This CSRF vulnerability in the bbPress Toolkit WordPress plugin allows attackers to trick authenticated administrators into performing unintended acti...

Nov 9, 2023
CVE-2023-34033
8.8

This CSRF vulnerability in the Malinky Ajax Pagination and Infinite Scroll WordPress plugin allows attackers to trick authenticated administrators int...

Nov 9, 2023
CVE-2023-34171
8.8

This CSRF vulnerability in the WP Report Post WordPress plugin allows attackers to trick authenticated users into performing unintended actions, such ...

Nov 9, 2023
CVE-2023-34178
8.8

This CSRF vulnerability in the Groundhogg WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. ...

Nov 9, 2023
CVE-2023-34182
8.8

This CSRF vulnerability in the LH Password Changer WordPress plugin allows attackers to trick authenticated administrators into performing unauthorize...

Nov 9, 2023
CVE-2023-47237
8.8

This CSRF vulnerability in the Auto Publish for Google My Business WordPress plugin allows attackers to trick authenticated administrators into perfor...

Nov 9, 2023
CVE-2023-31087
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the JoomSky JS Job Manager WordPress plugin allows attackers to trick authenticated administra...

Nov 9, 2023
CVE-2023-34386
8.8

This CSRF vulnerability in WPC Smart Wishlist for WooCommerce allows attackers to trick authenticated users into performing unintended actions on thei...

Nov 9, 2023
CVE-2023-25994
8.8

This CSRF vulnerability in the Publish to Schedule WordPress plugin allows attackers to trick authenticated administrators into performing unintended ...

Nov 9, 2023
CVE-2022-47181
8.8

This CSRF vulnerability in the Email Templates Customizer and Designer WordPress plugin allows attackers to trick authenticated administrators into pe...

Nov 7, 2023
CVE-2023-46776
8.8

This CSRF vulnerability in the Serena Villa Auto Excerpt Everywhere WordPress plugin allows attackers to trick authenticated administrators into perfo...

Nov 6, 2023
CVE-2023-46778
8.8

This CSRF vulnerability in the Auto Limit Posts Reloaded WordPress plugin allows attackers to trick authenticated administrators into performing unint...

Nov 6, 2023
CVE-2023-46780
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the WordPress Alter plugin allows attackers to trick authenticated administrators into perform...

Nov 6, 2023
CVE-2023-47186
8.8

This CSRF vulnerability in the Kadence WooCommerce Email Designer WordPress plugin allows attackers to trick authenticated administrators into perform...

Nov 6, 2023
CVE-2023-46775
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in the Djo Original texts Yandex WebMaster WordPress plugin allows attackers to trick authenticat...

Nov 6, 2023
CVE-2023-47182
8.8

This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Stored Cross-Site Scripting (XSS) in the Nazmul ...

Nov 6, 2023
CVE-2023-5893
8.8

This CSRF vulnerability in PKP-Lib allows attackers to trick authenticated users into performing unintended actions by submitting malicious requests. ...

Nov 1, 2023
CVE-2023-42323
8.8

This CSRF vulnerability in DouHaocms v3.3 allows attackers to trick authenticated administrators into executing arbitrary code by submitting forged re...

Oct 30, 2023
CVE-2023-46375
8.8

ZenTao Biz version 4.1.3 and earlier contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to trick authenticated users int...

Oct 27, 2023
CVE-2023-45317
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in an application interface that fails to validate HTTP requests. Attackers can t...

Oct 26, 2023
CVE-2023-5690
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in Modoboa email management platform allows attackers to trick authenticated users into performin...

Oct 20, 2023
CVE-2023-5687
8.8

This CSRF vulnerability in mosparo allows attackers to trick authenticated users into performing unintended actions on their behalf. It affects all us...

Oct 20, 2023
CVE-2022-2441
8.8

The ImageMagick Engine WordPress plugin up to version 1.7.5 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'cli_path' parameter tha...

Oct 20, 2023
CVE-2023-5626
8.8

This Cross-Site Request Forgery (CSRF) vulnerability in PKP Open Journal Systems (OJS) allows attackers to trick authenticated users into performing u...

Oct 18, 2023
CVE-2023-45902
8.8

Dreamer CMS v4.1.3 contains a Cross-Site Request Forgery (CSRF) vulnerability in the attachment deletion function. This allows attackers to trick auth...

Oct 17, 2023
CVE-2023-45904
8.8

Dreamer CMS v4.1.3 contains a CSRF vulnerability in the variable management modification function at /variable/update. This allows attackers to trick ...

Oct 17, 2023
CVE-2023-45906
8.8

Dreamer CMS v4.1.3 contains a CSRF vulnerability in the user addition function at /admin/user/add. This allows attackers to trick authenticated admini...

Oct 17, 2023
CVE-2023-43118
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in the Chalet application of Extreme Networks Switch Engine (EXOS) allows attackers to execute arbit...

Oct 16, 2023
CVE-2023-43149
8.8

SPA-Cart 1.9.0.3 has a CSRF vulnerability that allows attackers to create admin accounts with full privileges by tricking authenticated administrators...

Oct 12, 2023
CVE-2023-5511
8.8

This CSRF vulnerability in Snipe-IT allows attackers to trick authenticated users into performing unintended actions without their consent. It affects...

Oct 11, 2023
CVE-2023-4837
8.8

SmodBIP is vulnerable to Cross-Site Request Forgery (CSRF) that allows attackers to trick authenticated users into performing unintended actions. This...

Oct 10, 2023
CVE-2023-41086
8.8

This CSRF vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows attackers to perform unauthorized operations when authenticated use...

Oct 3, 2023
CVE-2023-41452
8.8

This CSRF vulnerability in phpkobo AjaxNewTicker v1.0.5 allows attackers to trick authenticated users into executing arbitrary code by submitting mali...

Sep 27, 2023
CVE-2023-35793
8.8

This CSRF vulnerability in Cassia Access Controller allows attackers to trick authenticated users into performing unauthorized web SSH actions to gate...

Sep 27, 2023
CVE-2023-43278
8.8

This CSRF vulnerability in Seacms allows attackers to create unauthorized admin accounts by tricking authenticated administrators into visiting malici...

Sep 25, 2023
CVE-2023-42321
8.8

This CSRF vulnerability in iCMSv.7.0.16 allows attackers to trick authenticated administrators into executing arbitrary code through malicious request...

Sep 20, 2023
CVE-2023-43500
8.8

This CSRF vulnerability in Jenkins Build Failure Analyzer Plugin allows attackers to trick authenticated users into making unauthorized connections to...

Sep 20, 2023
CVE-2023-5036
8.8

This CSRF vulnerability in the memos application allows attackers to trick authenticated users into performing unintended actions by crafting maliciou...

Sep 18, 2023
CVE-2023-42270
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Grocy versions up to 4.0.2. Attackers can trick authenticated users into perfo...

Sep 15, 2023
CVE-2023-40953
8.8

CVE-2023-40953 is a Cross-Site Request Forgery (CSRF) vulnerability in icms 7.0.16 that allows attackers to trick authenticated users into performing ...

Sep 8, 2023
CVE-2015-1391
8.8

CVE-2015-1391 is a Cross-Site Request Forgery (CSRF) vulnerability in Aruba AirWave network management software that allows attackers to bypass CSRF p...

Sep 5, 2023
CVE-2020-23595
8.8

A Cross-Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6 allows attackers to trick authenticated administrators into performing unautho...

Aug 11, 2023
CVE-2020-24922
8.8

This CSRF vulnerability in xxl-job-admin allows attackers to create admin users via crafted HTML files, leading to privilege escalation and potential ...

Aug 11, 2023
CVE-2023-38348
8.8

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Benno MailArchiv web application. Attackers can trick authenticated users into...

Aug 9, 2023
CVE-2023-31452
8.8

A CSRF token bypass vulnerability in PRTG Network Monitor versions 23.2.84.1566 and earlier allows attackers to trick authenticated users into perform...

Aug 9, 2023
CVE-2023-38759
8.8

This CSRF vulnerability in wger Workout Manager allows attackers to trick authenticated users into performing unintended actions, such as resetting pa...

Aug 8, 2023
CVE-2023-4047
8.8

This vulnerability allows attackers to manipulate popup notification timing in Firefox browsers, tricking users into granting unintended permissions. ...

Aug 1, 2023
CVE-2023-33534
8.8

This CSRF vulnerability in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software allows attackers to take over user accounts by tricking auth...

Jul 31, 2023
CVE-2022-43710
8.8

This CSRF vulnerability in GX Software XperienCentral's Interactive Forms allows attackers to trick authenticated users into performing unintended act...

Jul 26, 2023
CVE-2022-30280
8.8

This CSRF vulnerability in Nokia NetAct allows attackers to create users with arbitrary privileges, including administrative accounts, by tricking aut...

Jul 24, 2023

About Cross-Site Request Forgery (CSRF) (CWE-352)

The web application does not sufficiently verify that a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Our database tracks 2,376 CVEs classified as CWE-352, with 63 rated critical and 1,299 rated high severity. The average CVSS score for Cross-Site Request Forgery (CSRF) vulnerabilities is 6.7.

External reference: View CWE-352 on MITRE CWE →

Monitor Cross-Site Request Forgery (CSRF) Vulnerabilities

Get alerted when new Cross-Site Request Forgery (CSRF) CVEs affect your infrastructure.

Start Monitoring Free