The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could al
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
The wp-members plugin before 3.2.8 for WordPress has CSRF.
Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/c
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead t
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
The photo-gallery plugin before 1.2.42 for WordPress has CSRF.
The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.
The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
The avada theme before 5.1.5 for WordPress has CSRF.
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, r
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, r
Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay pr
Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows r
Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allo
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
NIUSHOP V1.11 has CSRF via search_info to index.php.
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.
The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.
The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the a
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.
TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.
Frequently Asked Questions
What is CWE-352?
CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-352?
There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.
How can I protect against CWE-352 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.
Detect CWE-352 Vulnerabilities
CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.
Get Started