A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescripto
A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote
The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configura
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
Bagisto 0.1.5 allows CSRF under /admin URIs.
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Ma
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actio
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An a
An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.1 for WordPress. wp-admin/ad
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_dat
In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forge
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
The js-jobs plugin before 1.0.7 for WordPress has CSRF.
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter n
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker
The user-access-manager plugin before 1.2 for WordPress has CSRF.
The user-domain-whitelist plugin before 1.5 for WordPress has CSRF.
The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute m
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
Frequently Asked Questions
What is CWE-352?
CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-352?
There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.
How can I protect against CWE-352 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.
Detect CWE-352 Vulnerabilities
CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.
Get Started