The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction
A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown
A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipu
A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability
A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown p
A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknow
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have auth
The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not s
The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could all
The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding
The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which co
The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints
The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, whic
The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could all
The WP Post Styling WordPress plugin before 1.3.1 does not have CSRF checks in various actions, which could allow attack
The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which c
The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which cou
The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its setting
The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which coul
The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could
The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow a
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attac
A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows
A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows at
A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows atta
The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its
The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which co
The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used
The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its
A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earl
A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and
In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to m
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place wh
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile
The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logge
The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make
The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow
The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing an
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some o
The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami Wor
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress.
An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can c
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in
A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problem
XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Re
Cross-Site Request Forgery (CSRF) vulnerability in Mickey Kay's Better Font Awesome plugin <= 2.0.1 at WordPress.
A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, po
Frequently Asked Questions
What is CWE-352?
CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-352?
There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.
How can I protect against CWE-352 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.
Detect CWE-352 Vulnerabilities
CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.
Get Started