CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,686 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 13 of 194
- CVE-2024-25418HIGHCVSS 8.8EG 8.82024-02-11
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.
- CVE-2024-25417HIGHCVSS 8.8EG 8.82024-02-11
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.
- CVE-2023-47020HIGHCVSS 8.8EG 8.82024-02-08
Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. T…
- CVE-2024-24469HIGHCVSS 8.8EG 8.82024-02-05
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
- CVE-2024-24468HIGHCVSS 8.8EG 8.82024-02-05
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.
- CVE-2024-24470HIGHCVSS 8.8EG 8.82024-02-02
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.
- CVE-2023-6676HIGHCVSS 8.8EG 8.82024-02-02
Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery. This issue affects CyberMath: from v1.4 before v1.5.
- CVE-2024-24524HIGHCVSS 8.8EG 8.82024-02-02
Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.
- CVE-2024-22859HIGHCVSS 8.8EG 8.82024-02-01
Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. NOTE: the vendor disputes this because the 5d88731 commit fixes a usability problem (HTTP 4…
- CVE-2024-22140HIGHCVSS 8.8EG 8.82024-01-31
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
- CVE-2023-7074HIGHCVSS 8.8EG 8.82024-01-29
The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- CVE-2023-6946HIGHCVSS 8.8EG 8.82024-01-29
The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- CVE-2023-6391HIGHCVSS 8.8EG 8.82024-01-29
The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- CVE-2023-6390HIGHCVSS 8.8EG 8.82024-01-29
The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- CVE-2023-47024HIGHCVSS 8.8EG 8.82024-01-20
Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed function in the WSDL that has weak security controls…
- CVE-2024-22819HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.
- CVE-2024-22818HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save
- CVE-2024-22817HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte
- CVE-2024-22603HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link
- CVE-2024-22601HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save
- CVE-2024-22699HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.
- CVE-2024-22593HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save
- CVE-2024-22592HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update
- CVE-2024-22591HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.
- CVE-2024-22568HIGHCVSS 8.8EG 8.82024-01-18
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.
- CVE-2024-22715HIGHCVSS 8.8EG 8.82024-01-17
Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
- CVE-2023-51063HIGHCVSS 8.8EG 8.82024-01-13
QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.
- CVE-2023-51949HIGHCVSS 8.8EG 8.82024-01-12
Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller
- CVE-2023-5448HIGHCVSS 8.8EG 8.82024-01-11
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on the update_password_validate function.…
- CVE-2023-52074HIGHCVSS 8.8EG 8.82024-01-08
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.
- CVE-2023-52073HIGHCVSS 8.8EG 8.82024-01-08
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.
- CVE-2023-52072HIGHCVSS 8.8EG 8.82024-01-08
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.
- CVE-2023-52216HIGHCVSS 8.8EG 8.82024-01-08
Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.
- CVE-2023-6845HIGHCVSS 8.8EG 8.82024-01-08
The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- CVE-2023-6532HIGHCVSS 8.8EG 8.82024-01-08
The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
- CVE-2023-52222HIGHCVSS 8.8EG 8.82024-01-08
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.
- CVE-2023-52122HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6.
- CVE-2023-52121HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in NitroPack Inc. NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images.This issue affects NitroPack – Cache & Speed Optimization for Core W…
- CVE-2023-52120HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder – Contact forms and much more: from n/a through 8.5.2.
- CVE-2023-52119HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA…
- CVE-2023-51668HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Inline Image Upload for BBPress.This issue affects Inline Image Upload for BBPress: from n/a through 1.1.18.
- CVE-2023-51539HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in Apollo13Themes Apollo13 Framework Extensions.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.1.
- CVE-2023-51538HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.5.
- CVE-2023-51535HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.
- CVE-2023-52149HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.
- CVE-2023-52145HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Republish Old Posts.This issue affects Republish Old Posts: from n/a through 1.21.
- CVE-2023-52136HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget or X Feed Widget: from n/a through 2.1.2.
- CVE-2023-52130HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.
- CVE-2023-52129HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.
- CVE-2023-52128HIGHCVSS 8.8EG 8.82024-01-05
Cross-Site Request Forgery (CSRF) vulnerability in WhiteWP White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard.This issue affects White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard: …
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →