CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,686 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 18 of 194
- CVE-2023-46193HIGHCVSS 8.8EG 8.82023-10-25
Cross-Site Request Forgery (CSRF) vulnerability in Internet Marketing Ninjas Internal Link Building plugin <= 1.2.3 versions.
- CVE-2023-46191HIGHCVSS 8.8EG 8.82023-10-25
Cross-Site Request Forgery (CSRF) vulnerability in Niels van Renselaar Open Graph Metabox plugin <= 1.4.4 versions.
- CVE-2023-46190HIGHCVSS 8.8EG 8.82023-10-25
Cross-Site Request Forgery (CSRF) vulnerability in Novo-media Novo-Map : your WP posts on custom google maps plugin <= 1.1.2 versions.
- CVE-2023-46189HIGHCVSS 8.8EG 8.82023-10-25
Cross-Site Request Forgery (CSRF) vulnerability in Simple Calendar – Google Calendar Plugin <= 3.2.5 versions.
- CVE-2023-46152HIGHCVSS 8.8EG 8.82023-10-25
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions.
- CVE-2023-46151HIGHCVSS 8.8EG 8.82023-10-25
Cross-Site Request Forgery (CSRF) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions.
- CVE-2023-46150HIGHCVSS 8.8EG 8.82023-10-25
Cross-Site Request Forgery (CSRF) vulnerability in WP Military WP Radio plugin <= 3.1.9 versions.
- CVE-2023-46095HIGHCVSS 8.8EG 8.82023-10-22
Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions.
- CVE-2023-46089HIGHCVSS 8.8EG 8.82023-10-22
Cross-Site Request Forgery (CSRF) vulnerability in Lee Le @ Userback Userback plugin <= 1.0.13 versions.
- CVE-2023-46085HIGHCVSS 8.8EG 8.82023-10-22
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.2.4 versions.
- CVE-2023-46078HIGHCVSS 8.8EG 8.82023-10-21
Cross-Site Request Forgery (CSRF) vulnerability in PluginEver WC Serial Numbers plugin <= 1.6.3 versions.
- CVE-2023-46067HIGHCVSS 8.8EG 8.82023-10-21
Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions.
- CVE-2023-5690HIGHCVSS 8.8EG 8.82023-10-20
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.
- CVE-2023-5687HIGHCVSS 8.8EG 8.82023-10-20
Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3.
- CVE-2023-5602HIGHCVSS 8.8EG 8.82023-10-20
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions c…
- CVE-2022-2441HIGHCVSS 8.8EG 8.82023-10-20
The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to r…
- CVE-2023-4920HIGHCVSS 8.8EG 8.82023-10-20
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticat…
- CVE-2023-44385HIGHCVSS 8.8EG 8.82023-10-19
The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when visited, will make the victim to call arbitrary services in…
- CVE-2023-42435HIGHCVSS 8.8EG 8.82023-10-19
The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to perform actions with the permissions of a victim user.
- CVE-2023-5626HIGHCVSS 8.8EG 8.82023-10-18
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.
- CVE-2023-45907HIGHCVSS 8.8EG 8.82023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.
- CVE-2023-45906HIGHCVSS 8.8EG 8.82023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.
- CVE-2023-45905HIGHCVSS 8.8EG 8.82023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.
- CVE-2023-45904HIGHCVSS 8.8EG 8.82023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.
- CVE-2023-45903HIGHCVSS 8.8EG 8.82023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.
- CVE-2023-45902HIGHCVSS 8.8EG 8.82023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.
- CVE-2023-45901HIGHCVSS 8.8EG 8.82023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.
- CVE-2023-45141HIGHCVSS 8.8EG 8.82023-10-16
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obtain tokens and forge malicious requests on behalf of a user.…
- CVE-2023-45128HIGHCVSS 8.8EG 8.82023-10-16
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to inject arbitrary values and forge malicious requests on behalf …
- CVE-2023-43118HIGHCVSS 8.8EG 8.82023-10-16
Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /js…
- CVE-2023-46087HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Mahlamusa Who Hit The Page – Hit Counter plugin <= 1.4.14.3 versions.
- CVE-2023-45836HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions.
- CVE-2023-45831HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Pixelative, Mohsin Rafique AMP WP – Google AMP For WordPress plugin <= 1.5.15 versions.
- CVE-2023-45763HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Taggbox plugin <= 2.9 versions.
- CVE-2023-45753HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Gilles Dumas which template file plugin <= 4.6.0 versions.
- CVE-2023-45752HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in 10 Quality Post Gallery plugin <= 2.3.12 versions.
- CVE-2023-45749HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions.
- CVE-2023-45748HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch plugin <= 3.1.4 versions.
- CVE-2023-45647HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in MailMunch Constant Contact Forms by MailMunch plugin <= 2.0.10 versions.
- CVE-2023-45645HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in InfoD74 WP Open Street Map plugin <= 1.25 versions.
- CVE-2023-45643HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Anurag Deshmukh CPT Shortcode Generator plugin <= 1.0 versions.
- CVE-2023-45642HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Hassan Ali Snap Pixel plugin <= 1.5.7 versions.
- CVE-2023-45641HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Caret Inc. Caret Country Access Limit plugin <= 1.0.2 versions.
- CVE-2023-45639HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Codex-m Sort SearchResult By Title plugin <= 10.0 versions.
- CVE-2023-4827HIGHCVSS 8.8EG 8.82023-10-16
The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using…
- CVE-2023-45656HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Kevin Weber Lazy Load for Videos plugin <= 2.18.2 versions.
- CVE-2023-45655HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.
- CVE-2023-45654HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.7 versions.
- CVE-2023-45653HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Video Playlist For YouTube plugin <= 6.0 versions.
- CVE-2023-45651HIGHCVSS 8.8EG 8.82023-10-16
Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi WP Attachments allows Cross Site Request Forgery.This issue affects WP Attachments: from n/a through 5.0.11.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →