AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by
ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credenti
Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator
Tina4 Stack 1.0.3 contains a cross-site request forgery vulnerability that allows attackers to modify admin user credent
Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin
OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create adm
Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabi
Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated a
Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform admini
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credenti
Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions
RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsd
OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthent
bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative a
Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform sta
jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user acco
Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their perm
Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro
HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords
PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administra
ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions o
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform un
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-
The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i
Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random pa
The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue
Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content
Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protecti
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, an ap
Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Reque
Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate cer
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate reque
GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the admi
Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_u
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affe
P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform admi
iDS6 DSSPro Digital Signage System 6.2 contains a cross-site request forgery vulnerability that allows attackers to perf
The MTCaptcha WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl
Frequently Asked Questions
What is CWE-352?
CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-352?
There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.
How can I protect against CWE-352 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.
Detect CWE-352 Vulnerabilities
CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.
Get Started