CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,686 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 11 of 194
- CVE-2024-41602HIGHCVSS 8.8EG 8.82024-07-19
Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privileges via a crafted URL
- CVE-2024-40119HIGHCVSS 8.8EG 8.82024-07-17
Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…
- CVE-2024-6075HIGHCVSS 8.8EG 8.82024-07-15
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- CVE-2024-5076HIGHCVSS 8.8EG 8.82024-07-13
The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- CVE-2024-5034HIGHCVSS 8.8EG 8.82024-07-13
The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- CVE-2024-6024HIGHCVSS 8.8EG 8.82024-07-12
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a logged in admin remove them via a CSRF attack
- CVE-2024-6023HIGHCVSS 8.8EG 8.82024-07-12
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack
- CVE-2024-6022HIGHCVSS 8.8EG 8.82024-07-12
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
- CVE-2024-1845HIGHCVSS 8.8EG 8.82024-07-11
The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- CVE-2024-40332HIGHCVSS 8.8EG 8.82024-07-10
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord
- CVE-2024-40331HIGHCVSS 8.8EG 8.82024-07-10
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup
- CVE-2024-40334HIGHCVSS 8.8EG 8.82024-07-10
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3
- CVE-2024-40329HIGHCVSS 8.8EG 8.82024-07-10
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup
- CVE-2024-28828HIGHCVSS 8.8EG 8.82024-07-10
Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.
- CVE-2024-39063HIGHCVSS 8.8EG 8.82024-07-09
Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.
- CVE-2024-40039HIGHCVSS 8.8EG 8.82024-07-09
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=del
- CVE-2024-40037HIGHCVSS 8.8EG 8.82024-07-09
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=del
- CVE-2024-40034HIGHCVSS 8.8EG 8.82024-07-09
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=del
- CVE-2024-6321HIGHCVSS 8.8EG 8.82024-07-09
The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.1.1. This is due to missing nonce validation and missing file type validation in the 'options…
- CVE-2024-6320HIGHCVSS 8.8EG 8.82024-07-09
The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.2.2. This is due to missing nonce validation and missing file type validation in the 'options_pa…
- CVE-2024-6317HIGHCVSS 8.8EG 8.82024-07-09
The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 4.1.2. This is due to missing nonce validation and the plugin not properly va…
- CVE-2024-6316HIGHCVSS 8.8EG 8.82024-07-09
The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 4.1.2. This is due to missing nonce validation and missing file type validati…
- CVE-2024-6310HIGHCVSS 8.8EG 8.82024-07-09
The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 2.7.7. This is due to missing nonce validation in the 'admin_init_AAPL' function and …
- CVE-2024-6309HIGHCVSS 8.8EG 8.82024-07-09
The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.3. This is due to missing nonce validation in the 'afi_overview' function an…
- CVE-2023-47677HIGHCVSS 8.8EG 8.82024-07-08
A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger …
- CVE-2024-39023HIGHCVSS 8.8EG 8.82024-07-05
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close
- CVE-2024-39022HIGHCVSS 8.8EG 8.82024-07-05
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal
- CVE-2024-5943HIGHCVSS 8.8EG 8.82024-07-04
The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing or incorrect nonce validation on the 'settingsPage' function and missing santization of t…
- CVE-2024-2376HIGHCVSS 8.8EG 8.82024-07-03
The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- CVE-2024-5767HIGHCVSS 8.8EG 8.82024-07-02
The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
- CVE-2024-23736HIGHCVSS 8.8EG 8.82024-07-01
Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email.
- CVE-2024-39158HIGHCVSS 8.8EG 8.82024-06-27
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.
- CVE-2024-39154HIGHCVSS 8.8EG 8.82024-06-27
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.
- CVE-2024-5343HIGHCVSS 8.8EG 8.82024-06-19
The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due to missing or incorrect nonce validation on the 'rbs_ajax_cre…
- CVE-2024-38276HIGHCVSS 8.8EG 8.82024-06-18
Incorrect CSRF token checks resulted in multiple CSRF risks.
- CVE-2024-38457HIGHCVSS 8.8EG 8.82024-06-16
Xenforo before 2.2.16 allows CSRF.
- CVE-2024-4403HIGHCVSS 8.8EG 8.82024-06-10
A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows attackers to trick users into performing unintended actions, such as resetting the progra…
- CVE-2024-1879HIGHCVSS 8.8EG 8.82024-06-06
A Cross-Site Request Forgery (CSRF) vulnerability in significant-gravitas/autogpt version v0.5.0 allows attackers to execute arbitrary commands on the AutoGPT server. The vulnerability stems from the lack of protections on the API endpoint…
- CVE-2024-36670HIGHCVSS 8.8EG 8.82024-06-05
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=del
- CVE-2024-36669HIGHCVSS 8.8EG 8.82024-06-05
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.
- CVE-2024-36668HIGHCVSS 8.8EG 8.82024-06-05
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del
- CVE-2024-36667HIGHCVSS 8.8EG 8.82024-06-05
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProType_deal.php?mudi=add&nohrefStr=close
- CVE-2024-36550HIGHCVSS 8.8EG 8.82024-06-04
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close
- CVE-2024-36549HIGHCVSS 8.8EG 8.82024-06-04
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close
- CVE-2024-36548HIGHCVSS 8.8EG 8.82024-06-04
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del
- CVE-2024-36547HIGHCVSS 8.8EG 8.82024-06-04
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add
- CVE-2024-34008HIGHCVSS 8.8EG 8.82024-05-31
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
- CVE-2024-34007HIGHCVSS 8.8EG 8.82024-05-31
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
- CVE-2024-4535HIGHCVSS 8.8EG 8.82024-05-27
The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- CVE-2024-35559HIGHCVSS 8.8EG 8.82024-05-22
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →