Cross-Site Request Forgery (CSRF) vulnerability in Sucuri Security plugin <= 1.8.33 at WordPress leading to Event log en
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.
The WordPress Ping Optimizer WordPress plugin before 2.35.1.3.0 does not have CSRF check in place when updating its sett
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress.
Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress.
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowin
The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which c
A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.
The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could
The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could
A vulnerability has been found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic
A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Af
A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to conne
Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress.
The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history,
The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple A
Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Order Export For WooCommerce plugin <= 3.3.2 on WordPress le
A vulnerability, which was classified as problematic, was found in NodeBB up to 2.5.7. This affects an unknown part of t
A cross-site request forgery (CSRF) vulnerability in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attacker
A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an
A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown
Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unau
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenti
A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unkno
Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress.
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attack
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou
Cross-Site Request Forgery (CSRF) vulnerability in Oceanwp sticky header plugin <= 1.0.8 on WordPress.
A vulnerability classified as problematic has been found in CTF-hacker pwn. This affects an unknown part of the file del
A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown f
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions
A vulnerability classified as problematic has been found in University of Central Florida Materia up to 9.0.0. This affe
A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerab
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popup
A vulnerability was found in sah-comp bienlein and classified as problematic. This issue affects some unknown processing
A vulnerability was found in Pengu. It has been declared as problematic. Affected by this vulnerability is the function
A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown p
A vulnerability was found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this issue is som
A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown f
A vulnerability was found in destiny.gg chat. It has been rated as problematic. This issue affects the function websocke
A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function
A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerabi
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
A vulnerability was found in valtech IDP Test Client and classified as problematic. Affected by this issue is some unkno
Frequently Asked Questions
What is CWE-352?
CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-352?
There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.
How can I protect against CWE-352 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.
Detect CWE-352 Vulnerabilities
CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.
Get Started