CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,685 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 2 of 194
- CVE-2025-32281CRITICALCVSS 4.3EG 9.82025-06-27
Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite darkmysite allows Cross Site Request Forgery.This issue affects DarkMySite: from n/a through <= 1.2.8.
- CVE-2026-56662CRITICALCVSS 9.6EG 9.62026-10-01
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-…
- CVE-2026-28164CRITICALCVSS 9.6EG 9.62026-08-20
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.
- CVE-2026-46409CRITICALCVSS 9.6EG 9.62026-08-07
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without serve…
- CVE-2026-70376CRITICALCVSS 9.6EG 9.62026-08-05
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin a…
- CVE-2026-65471CRITICALCVSS 9.6EG 9.62026-07-23
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
- CVE-2026-57784CRITICALCVSS 9.6EG 9.62026-07-23
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
- CVE-2026-61097CRITICALCVSS 9.6EG 9.62026-07-21
Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable vulnerability allows un…
- CVE-2026-53649CRITICALCVSS 9.6EG 9.62026-07-08
Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safeliste…
- CVE-2026-55742CRITICALCVSS 9.6EG 9.62026-06-18
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (includin…
- CVE-2026-46786CRITICALCVSS 9.6EG 9.62026-06-17
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-40471CRITICALCVSS 9.6EG 9.62026-04-23
hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrat…
- CVE-2026-39640CRITICALCVSS 9.6EG 9.62026-04-08
Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.
- CVE-2026-39620CRITICALCVSS 9.6EG 9.62026-04-08
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.
- CVE-2026-39619CRITICALCVSS 9.6EG 9.62026-04-08
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.
- CVE-2026-39617CRITICALCVSS 9.6EG 9.62026-04-08
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.
- CVE-2025-52835CRITICALCVSS 9.6EG 9.62025-12-30
Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a Web Shell to a Web Server.This issue affects WING WordPress Migrator: from n/a through <= 1.2.0.
- CVE-2025-11022CRITICALCVSS 9.6EG 9.62025-12-09
Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery. This CSRF vulnerability resulting in Command Injection has been identified. This issue affects Panilux: before v.0.10.…
- CVE-2024-45538CRITICALCVSS 9.6EG 9.62025-12-04
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute ar…
- CVE-2025-60739CRITICALCVSS 9.6EG 9.62025-11-25
Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component
- CVE-2025-60156CRITICALCVSS 9.6EG 9.62025-09-26
Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 8.34.
- CVE-2025-58255CRITICALCVSS 9.6EG 9.62025-09-22
Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Images custom-post-types-image allows Code Injection.This issue affects Custom Post Type Images: from n/a through <= 0.5.
- CVE-2025-58997CRITICALCVSS 9.6EG 9.62025-09-09
Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/a through <= 4.10.
- CVE-2025-49381CRITICALCVSS 9.6EG 9.62025-08-20
Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Site Request Forgery.This issue affects ads.txt Guru Connect: from n/a through <= 1.1.1.
- CVE-2025-54010CRITICALCVSS 9.6EG 9.62025-07-16
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Request Forgery.This issue affects FluentSnippets: from n/a through <= 10.50.
- CVE-2025-53095CRITICALCVSS 9.6EG 9.62025-07-01
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows an attacker to craft a malicious…
- CVE-2025-53314CRITICALCVSS 9.6EG 9.62025-06-27
Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a through <= 2.5.0.
- CVE-2025-39601CRITICALCVSS 9.6EG 9.62025-04-16
Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusion.This issue affects Custom CSS, JS & PHP: from n/a through <= 2.4.1.
- CVE-2025-30967CRITICALCVSS 9.6EG 9.62025-04-15
Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.
- CVE-2025-32641CRITICALCVSS 9.6EG 9.62025-04-09
Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forgery.This issue affects Anant Addons for Elementor: from n/a through <= 1.1.8.
- CVE-2025-32576CRITICALCVSS 9.6EG 9.62025-04-09
Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web Shell to a Web Server.This issue affects WP shop: from n/a through <= 2.6.1.
- CVE-2025-32496CRITICALCVSS 9.6EG 9.62025-04-09
Cross-Site Request Forgery (CSRF) vulnerability in Uncodethemes Ultra Demo Importer ut-demo-importer allows Upload a Web Shell to a Web Server.This issue affects Ultra Demo Importer: from n/a through <= 1.0.5.
- CVE-2025-30615CRITICALCVSS 9.6EG 9.62025-03-24
Cross-Site Request Forgery (CSRF) vulnerability in Jacob Schwartz WP e-Commerce Style Email wp-e-commerce-style-email allows Code Injection.This issue affects WP e-Commerce Style Email: from n/a through <= 0.6.2.
- CVE-2024-7760CRITICALCVSS 9.6EG 9.62025-03-20
aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF …
- CVE-2025-25379CRITICALCVSS 9.6EG 9.62025-02-28
Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.
- CVE-2025-25107CRITICALCVSS 9.6EG 9.62025-02-07
Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forgery.This issue affects OneStore Sites: from n/a through <= 0.1.1.
- CVE-2025-25106CRITICALCVSS 9.6EG 9.62025-02-07
Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP starter-templates allows Cross Site Request Forgery.This issue affects Starter Templates by FancyWP: from n/a through <= 2.0.0.
- CVE-2025-25101CRITICALCVSS 9.6EG 9.62025-02-07
Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites munk-sites allows Cross Site Request Forgery.This issue affects Munk Sites: from n/a through <= 1.0.7.
- CVE-2024-54372CRITICALCVSS 9.6EG 9.62024-12-16
Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify insertify allows Code Injection.This issue affects Insertify: from n/a through <= 1.1.4.
- CVE-2024-54368CRITICALCVSS 9.6EG 9.62024-12-16
Cross-Site Request Forgery (CSRF) vulnerability in rubengarzajr GitSync git-sync allows Code Injection.This issue affects GitSync: from n/a through <= 1.1.0.
- CVE-2024-52402CRITICALCVSS 9.6EG 9.62024-11-19
Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-password-protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a th…
- CVE-2024-52401CRITICALCVSS 9.6EG 9.62024-11-19
Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog DownloadManager hacklog-downloadmanager allows Upload a Web Shell to a Web Server.This issue affects Hacklog DownloadManager: from n/a through <= 2.1.4.
- CVE-2024-49674CRITICALCVSS 9.6EG 9.62024-10-31
Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through <= 2.2.1.
- CVE-2024-43984CRITICALCVSS 9.6EG 9.62024-10-31
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
- CVE-2024-8980CRITICALCVSS 9.6EG 9.62024-10-22
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack …
- CVE-2024-7568CRITICALCVSS 9.6EG 9.62024-08-24
The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the output_sub_admin_page_0 function. This makes it possi…
- CVE-2024-41603CRITICALCVSS 9.6EG 9.62024-07-19
Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.
- CVE-2024-38293CRITICALCVSS 9.6EG 9.62024-06-13
ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
- CVE-2024-33913CRITICALCVSS 9.6EG 9.62024-05-02
Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects Xserver Migrator: from n/a through 1.6.1.
- CVE-2024-30560CRITICALCVSS 9.6EG 9.62024-04-25
Cross-Site Request Forgery (CSRF) vulnerability in 大侠WP DX-Watermark.This issue affects DX-Watermark: from n/a through 1.0.4.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →