Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-352

MITRE ↗

Cross-Site Request Forgery (CSRF)

134
CRITICAL
3,349
HIGH
4,754
MEDIUM
98
LOW
8,392 CVEs · Page 147/168
8.8
CVE-2016-10903

The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.

8.8
CVE-2017-18521

The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage

8.8
CVE-2019-12624

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could al

8.8
CVE-2019-13477

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to

8.8
CVE-2016-10918

The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.

8.8
CVE-2019-15329

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

8.8
CVE-2019-15491

openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.

8.8
CVE-2015-9343

The wp-rollback plugin before 1.2.3 for WordPress has CSRF.

8.8
CVE-2018-21002

The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.

8.8
CVE-2018-21006

The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.

8.8
CVE-2019-15645

The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.

8.8
CVE-2019-15660

The wp-members plugin before 3.2.8 for WordPress has CSRF.

8.8
CVE-2019-11457

Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/c

8.8
CVE-2019-10384

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session

8.8
CVE-2019-15496

MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead t

8.8
CVE-2019-15769

The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.

8.8
CVE-2019-15770

The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.

8.8
CVE-2019-15779

The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_

8.8
CVE-2019-15781

The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.

8.8
CVE-2015-9380

The photo-gallery plugin before 1.2.42 for WordPress has CSRF.

8.8
CVE-2019-15828

The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.

8.8
CVE-2019-15831

The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.

8.8
CVE-2019-15832

The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.

8.8
CVE-2019-15834

The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.

8.8
CVE-2019-15835

The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.

8.8
CVE-2019-15840

The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.

8.8
CVE-2019-15841

The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in

8.8
CVE-2019-15865

The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.

8.8
CVE-2019-15868

The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.

8.8
CVE-2019-16059

Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary

8.8
CVE-2019-16099

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.

8.8
CVE-2017-18607

The avada theme before 5.1.5 for WordPress has CSRF.

8.8
CVE-2019-1259

A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, r

8.8
CVE-2019-1261

A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, r

8.8
CVE-2019-5986

Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay pr

8.8
CVE-2019-5992

Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows r

8.8
CVE-2019-5993

Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allo

8.8
CVE-2016-10944

The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.

8.8
CVE-2016-10945

The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.

8.8
CVE-2016-10946

The wp-d3 plugin before 2.4.1 for WordPress has CSRF.

8.8
CVE-2019-16311

NIUSHOP V1.11 has CSRF via search_info to index.php.

8.8
CVE-2016-10974

The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.

8.8
CVE-2016-10978

The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.

8.8
CVE-2016-10982

The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.

8.8
CVE-2016-10989

The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.

8.8
CVE-2019-16531

LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.

8.8
CVE-2019-15089

An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the a

8.8
CVE-2015-9394

The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.

8.8
CVE-2019-16658

TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.

8.8
CVE-2019-16659

TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.

Frequently Asked Questions

What is CWE-352?

CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-352?

There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.

How can I protect against CWE-352 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.

Detect CWE-352 Vulnerabilities

CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.

Get Started