CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,686 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 15 of 194
- CVE-2023-49834HIGHCVSS 8.8EG 8.82023-12-17
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4.
- CVE-2023-49824HIGHCVSS 8.8EG 8.82023-12-17
Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2.1.1.
- CVE-2023-49816HIGHCVSS 8.8EG 8.82023-12-17
Cross-Site Request Forgery (CSRF) vulnerability in Innovative Solutions Fix My Feed RSS Repair.This issue affects Fix My Feed RSS Repair: from n/a through 1.4.
- CVE-2023-49775HIGHCVSS 8.8EG 8.82023-12-17
Cross-Site Request Forgery (CSRF) vulnerability in Denis Kobozev CSV Importer.This issue affects CSV Importer: from n/a through 0.3.8.
- CVE-2023-49769HIGHCVSS 8.8EG 8.82023-12-17
Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4.
- CVE-2023-49751HIGHCVSS 8.8EG 8.82023-12-17
Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu Block for Font Awesome.This issue affects Block for Font Awesome: from n/a through 1.4.0.
- CVE-2023-50722HIGHCVSS 8.8EG 8.82023-12-15
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sec…
- CVE-2023-49749HIGHCVSS 8.8EG 8.82023-12-15
Cross-Site Request Forgery (CSRF) vulnerability in SureTriggers SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything!.This issue affects SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything!:…
- CVE-2023-49744HIGHCVSS 8.8EG 8.82023-12-15
Cross-Site Request Forgery (CSRF) vulnerability in Gift Up Gift Up Gift Cards for WordPress and WooCommerce.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through 2.21.3.
- CVE-2023-49197HIGHCVSS 8.8EG 8.82023-12-15
Cross-Site Request Forgery (CSRF) vulnerability in Apasionados, Apasionados del Marketing, NetConsulting DoFollow Case by Case.This issue affects DoFollow Case by Case: from n/a through 3.4.2.
- CVE-2023-50870HIGHCVSS 8.8EG 8.82023-12-15
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
- CVE-2023-50017HIGHCVSS 8.8EG 8.82023-12-14
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backup
- CVE-2023-50778HIGHCVSS 8.8EG 8.82023-12-13
A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified token.
- CVE-2023-50768HIGHCVSS 8.8EG 8.82023-12-13
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another met…
- CVE-2023-50766HIGHCVSS 8.8EG 8.82023-12-13
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.
- CVE-2023-47326HIGHCVSS 8.8EG 8.82023-12-13
Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.
- CVE-2023-47322HIGHCVSS 8.8EG 8.82023-12-13
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the …
- CVE-2023-47578HIGHCVSS 8.8EG 8.82023-12-13
Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absence of CSRF protection in the web interface.
- CVE-2023-45316HIGHCVSS 8.8EG 8.82023-12-12
Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to …
- CVE-2023-6671HIGHCVSS 8.8EG 8.82023-12-11
A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.
- CVE-2023-5756HIGHCVSS 8.8EG 8.82023-12-09
The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it …
- CVE-2023-49448HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
- CVE-2023-49447HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
- CVE-2023-49446HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.
- CVE-2023-49398HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
- CVE-2023-49397HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
- CVE-2023-49396HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
- CVE-2023-49395HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
- CVE-2023-49383HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
- CVE-2023-49382HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
- CVE-2023-49381HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
- CVE-2023-49380HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
- CVE-2023-49379HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.
- CVE-2023-49378HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.
- CVE-2023-49377HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
- CVE-2023-49376HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.
- CVE-2023-49375HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.
- CVE-2023-49374HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.
- CVE-2023-49373HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.
- CVE-2023-49372HIGHCVSS 8.8EG 8.82023-12-05
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.
- CVE-2023-24048HIGHCVSS 8.8EG 8.82023-12-04
Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm.
- CVE-2023-47870HIGHCVSS 8.8EG 8.82023-11-30
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.Thi…
- CVE-2023-47875HIGHCVSS 8.8EG 8.82023-11-30
Cross-Site Request Forgery (CSRF) vulnerability in Perfmatters allows Cross Site Request Forgery.This issue affects Perfmatters: from n/a through 2.1.6.
- CVE-2023-5803HIGHCVSS 8.8EG 8.82023-11-30
Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows Cross-Site Request Forgery.This issue affects Business Directory Plugin – Easy Listing…
- CVE-2023-48754HIGHCVSS 8.8EG 8.82023-11-30
Cross-Site Request Forgery (CSRF) vulnerability in Wap Nepal Delete Post Revisions In WordPress allows Cross Site Request Forgery.This issue affects Delete Post Revisions In WordPress: from n/a through 4.6.
- CVE-2023-48328HIGHCVSS 8.8EG 8.82023-11-30
Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue affects WordPress Gallery Plugin – NextGEN Gallery: from n/a through 3.37.
- CVE-2023-48914HIGHCVSS 8.8EG 8.82023-11-30
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/add.
- CVE-2023-48913HIGHCVSS 8.8EG 8.82023-11-30
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/delete.
- CVE-2023-48912HIGHCVSS 8.8EG 8.82023-11-30
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/edit.
- CVE-2023-48281HIGHCVSS 8.8EG 8.82023-11-30
Cross-Site Request Forgery (CSRF) vulnerability in Super Blog Me Broken Link Checker for YouTube allows Cross Site Request Forgery.This issue affects Broken Link Checker for YouTube: from n/a through 1.3.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →