CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,685 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 4 of 194
- CVE-2023-1722CRITICALCVSS 9.1EG 9.12023-06-24
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.
- CVE-2023-23465CRITICALCVSS 9.1EG 9.12023-02-15
Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.
- CVE-2018-20577CRITICALCVSS 9.1EG 9.12018-12-28
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Mo…
- CVE-2024-55089CRITICALCVSS 4.1EG 9.12024-12-18
Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because XML documents may contain external entities.
- CVE-2026-61204CRITICALCVSS 9.0EG 9.02026-07-21
Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged atta…
- CVE-2025-69634CRITICALCVSS 9.0EG 9.02026-02-12
Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur…
- CVE-2025-26206CRITICALCVSS 9.0EG 9.02025-03-03
Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component
- CVE-2024-31986CRITICALCVSS 9.0EG 9.02024-04-10
XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a special crafted documented reference and an `XWiki.SchedulerJobClass` XObject, it is po…
- CVE-2023-40572CRITICALCVSS 9.0EG 9.02023-08-24
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/pro…
- CVE-2023-29213CRITICALCVSS 9.0EG 9.02023-04-17
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:xwiki-platform-logging-ui` it is possible to trick a user with programming rights into vis…
- CVE-2023-22457CRITICALCVSS 9.0EG 9.02023-01-04
CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the …
- CVE-2021-24922CRITICALCVSS 9.0EG 9.02021-12-13
The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scr…
- CVE-2019-19915CRITICALCVSS 9.0EG 9.02019-12-19
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save a…
- CVE-2022-41622CRITICALCVSS 8.8EG 9.02022-12-07
In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2018-7700CRITICALCVSS 8.8EG 9.02018-03-27
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
- CVE-2023-39446HIGHCVSS 8.9EG 8.92023-09-18
Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a…
- CVE-2025-54782HIGHCVSS 8.8EG 8.92025-08-02
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the pac…
- CVE-2019-16667HIGHCVSS 8.8EG 8.92019-09-26
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a…
- CVE-2026-107809HIGHCVSS 8.8EG 8.82026-10-09
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do …
- CVE-2026-96671HIGHCVSS 8.8EG 8.82026-10-09
Cross-Site Request Forgery (CSRF) vulnerability in fifu.app Featured Image from URL featured-image-from-url allows Cross Site Request Forgery.This issue affects Featured Image from URL: from n/a through 6.0.7.
- CVE-2026-78388HIGHCVSS 8.8EG 8.82026-10-08
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a …
- CVE-2026-62142HIGHCVSS 8.8EG 8.82026-10-08
Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a through 4.1.0.
- CVE-2025-70517HIGHCVSS 8.8EG 8.82026-10-07
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can…
- CVE-2025-70522HIGHCVSS 8.8EG 8.82026-10-07
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can…
- CVE-2026-93549HIGHCVSS 8.8EG 8.82026-10-04
The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection for every route, allowing an attacker to perform a cross-site request f…
- CVE-2026-39718HIGHCVSS 8.8EG 8.82026-10-02
Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.
- CVE-2026-101147HIGHCVSS 8.8EG 8.82026-10-01
The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted UR…
- CVE-2026-96838HIGHCVSS 8.8EG 8.82026-09-30
Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions.
- CVE-2026-95362HIGHCVSS 8.8EG 8.82026-09-29
Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-67993HIGHCVSS 8.8EG 8.82026-09-29
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.
- CVE-2026-96524HIGHCVSS 8.8EG 8.82026-09-26
The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers …
- CVE-2026-62062HIGHCVSS 8.8EG 8.82026-09-25
Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1.
- CVE-2026-88418HIGHCVSS 8.8EG 8.82026-09-22
CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentic…
- CVE-2026-84084HIGHCVSS 8.8EG 8.82026-09-18
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.
- CVE-2026-78295HIGHCVSS 8.8EG 8.82026-09-17
Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
- CVE-2026-82712HIGHCVSS 8.8EG 8.82026-09-04
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
- CVE-2026-85236HIGHCVSS 8.8EG 8.82026-09-03
A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not …
- CVE-2026-84649HIGHCVSS 8.8EG 8.82026-09-02
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint servin…
- CVE-2026-84770HIGHCVSS 8.8EG 8.82026-09-02
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
- CVE-2026-84764HIGHCVSS 8.8EG 8.82026-09-02
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
- CVE-2026-75814HIGHCVSS 8.8EG 8.82026-08-27
The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, caus…
- CVE-2026-81271HIGHCVSS 8.8EG 8.82026-08-27
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
- CVE-2025-56798HIGHCVSS 8.8EG 8.82026-08-26
Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy.
- CVE-2026-71694HIGHCVSS 8.8EG 8.82026-08-19
An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling logic…
- CVE-2026-66602HIGHCVSS 8.8EG 8.82026-08-18
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
- CVE-2026-73222HIGHCVSS 8.8EG 8.82026-08-11
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits …
- CVE-2026-72578HIGHCVSS 8.8EG 8.82026-08-10
A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.
- CVE-2026-70432HIGHCVSS 8.8EG 8.82026-08-05
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.
- CVE-2026-7326HIGHCVSS 8.8EG 8.82026-08-05
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on…
- CVE-2026-60009HIGHCVSS 8.8EG 8.82026-08-05
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and…
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →