Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-352

MITRE ↗

Cross-Site Request Forgery (CSRF)

134
CRITICAL
3,349
HIGH
4,754
MEDIUM
98
LOW
8,392 CVEs · Page 146/168
8.8
CVE-2019-10386

A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescripto

8.8
CVE-2019-1958

A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote

8.8
CVE-2019-14681

The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove

8.8
CVE-2015-9292

6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).

8.8
CVE-2016-10862

Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configura

8.8
CVE-2016-10863

Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.

8.8
CVE-2019-14933

Bagisto 0.1.5 allows CSRF under /admin URIs.

8.8
CVE-2016-10874

The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.

8.8
CVE-2016-10876

The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.

8.8
CVE-2017-18504

The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.

8.8
CVE-2018-20964

The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.

8.8
CVE-2019-11207

The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Ma

8.8
CVE-2013-7476

The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.

8.8
CVE-2015-9307

The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.

8.8
CVE-2015-9308

The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

8.8
CVE-2015-9309

The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.

8.8
CVE-2016-10882

The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.

8.8
CVE-2016-10884

The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.

8.8
CVE-2016-10885

The wp-editor plugin before 1.2.6 for WordPress has CSRF.

8.8
CVE-2017-18510

The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actio

8.8
CVE-2017-18511

The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.

8.8
CVE-2017-18512

The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.

8.8
CVE-2017-18513

The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.

8.8
CVE-2018-20967

The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.

8.8
CVE-2018-20968

The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.

8.8
CVE-2019-10199

It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An a

8.8
CVE-2019-14216

An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/ad

8.8
CVE-2018-14668

In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_dat

8.8
CVE-2019-13516

In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forge

8.8
CVE-2015-9322

The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.

8.8
CVE-2017-18544

The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.

8.8
CVE-2017-18546

The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.

8.8
CVE-2017-18547

The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.

8.8
CVE-2018-20971

The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.

8.8
CVE-2018-20972

The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.

8.8
CVE-2018-20974

The js-jobs plugin before 1.0.7 for WordPress has CSRF.

8.8
CVE-2019-15113

The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.

8.8
CVE-2019-15114

The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.

8.8
CVE-2019-15115

The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.

8.8
CVE-2019-15150

In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter n

8.8
CVE-2019-15229

FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker

8.8
CVE-2011-5328

The user-access-manager plugin before 1.2 for WordPress has CSRF.

8.8
CVE-2014-10381

The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.

8.8
CVE-2016-10914

The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.

8.8
CVE-2016-10915

The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.

8.8
CVE-2017-18569

The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.

8.8
CVE-2019-15238

The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.

8.8
CVE-2017-18523

The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.

8.8
CVE-2019-4117

IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute m

8.8
CVE-2016-10902

The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.

Frequently Asked Questions

What is CWE-352?

CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-352?

There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.

How can I protect against CWE-352 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.

Detect CWE-352 Vulnerabilities

CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.

Get Started