Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-352

MITRE ↗

Cross-Site Request Forgery (CSRF)

134
CRITICAL
3,349
HIGH
4,754
MEDIUM
98
LOW
8,392 CVEs · Page 159/168
8.8
CVE-2018-18191

Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote

8.8
CVE-2018-17858

An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the bac

8.8
CVE-2018-18201

qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.

8.8
CVE-2018-12456

Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attacker

8.8
CVE-2018-18215

In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.

8.8
CVE-2018-18316

emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.

8.8
CVE-2018-18317

DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.

8.8
CVE-2018-15539

Agentejo Cockpit lacks an anti-CSRF protection mechanism. Thus, an attacker is able to change API tokens, passwords, etc

8.8
CVE-2018-18422

UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.

8.8
CVE-2018-18432

An issue was discovered in DESTOON B2B 7.0. CSRF exists via the admin.php URI in an action=add request.

8.8
CVE-2018-18436

JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.

8.8
CVE-2018-12364

NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin PO

8.8
CVE-2018-12370

In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Re

8.8
CVE-2018-18420

Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System v

8.8
CVE-2018-9281

An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the

8.8
CVE-2018-18711

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's pass

8.8
CVE-2018-18712

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's user

8.8
CVE-2018-18734

A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.

8.8
CVE-2018-18735

A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

8.8
CVE-2018-18742

A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.

8.8
CVE-2018-18842

CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to e

8.8
CVE-2018-6907

A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch

8.8
CVE-2018-18935

An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as dem

8.8
CVE-2018-19104

In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server pr

8.8
CVE-2018-19138

WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.

8.8
CVE-2017-17550

ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd actio

8.8
CVE-2018-19135

ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an

8.8
CVE-2018-19192

An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by enteri

8.8
CVE-2018-19225

An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF.

8.8
CVE-2018-18794

School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.

8.8
CVE-2018-18797

School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.

8.8
CVE-2018-18799

School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.

8.8
CVE-2018-19318

SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super admini

8.8
CVE-2018-19327

An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.

8.8
CVE-2018-19332

An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type

8.8
CVE-2018-18772

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem

8.8
CVE-2018-18773

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demo

8.8
CVE-2018-19545

JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.

8.8
CVE-2018-19546

JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload

8.8
CVE-2018-19555

tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.

8.8
CVE-2018-19560

BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

8.8
CVE-2018-19561

sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.

8.8
CVE-2018-14892

Missing protections against Cross-Site Request Forgery in the web application in ZyXEL NSA325 V2 version 4.81 allow atta

8.8
CVE-2018-7831

An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded we

8.8
CVE-2018-16634

Pluck v4.7.7 allows CSRF via admin.php?action=settings.

8.8
CVE-2018-19923

An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php

8.8
CVE-2018-20015

YzmCMS v5.2 has admin/role/add.html CSRF.

8.8
CVE-2018-19969

phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clic

8.8
CVE-2018-20188

FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.

8.8
CVE-2018-20231

Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote atta

Frequently Asked Questions

What is CWE-352?

CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-352?

There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.

How can I protect against CWE-352 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.

Detect CWE-352 Vulnerabilities

CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.

Get Started