Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-352

MITRE ↗

Cross-Site Request Forgery (CSRF)

134
CRITICAL
3,349
HIGH
4,754
MEDIUM
98
LOW
8,392 CVEs · Page 16/168
4.3
CVE-2026-13422

The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to

4.3
CVE-2026-13537

A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipu

4.3
CVE-2026-8944

The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in v

4.3
CVE-2026-13946

Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacke

4.3
CVE-2026-13952

Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to lea

4.3
CVE-2026-11981

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 Thi

4.3
CVE-2026-57690

Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.

4.3
CVE-2026-59520

Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This i

4.3
CVE-2026-14800

A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affecte

4.3
CVE-2026-58315

Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged

4.3
CVE-2026-9731

The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,

4.3
CVE-2026-15034

A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some

4.3
CVE-2026-6440

The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cro

4.3
CVE-2026-15080

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Ray Enterprise Translation allows Cross Site Request Forgery.

4.3
CVE-2026-61502

Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its

4.3
CVE-2026-12409

The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress i

4.3
CVE-2026-9734

The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a

4.3
CVE-2026-16081

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file w

4.3
CVE-2026-16216

A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAu

4.3
CVE-2026-32823

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

4.3
CVE-2026-64821

djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated

4.3
CVE-2026-24537

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

4.3
CVE-2026-65460

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

4.3
CVE-2026-66428

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

4.3
CVE-2026-66474

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

4.3
CVE-2026-15136

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery

4.3
CVE-2026-9720

The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions

4.3
CVE-2026-5582

The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24

4.3
CVE-2026-13729

The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrat

4.3
CVE-2025-14469

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,

4.3
CVE-2026-18819

A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul

4.3
CVE-2026-16613

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable

4.3
CVE-2026-17515

The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio

4.3
CVE-2026-70556

Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h

4.3
CVE-2026-66681

Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.

4.3
CVE-2026-16965

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a

4.3
CVE-2026-66775

SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent

4.3
CVE-2026-47232

Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modu

4.3
CVE-2026-19786

A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the fi

4.3
CVE-2025-10308

The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc

4.3
CVE-2026-75151

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vu

4.3
CVE-2026-40509

OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter

4.3
CVE-2026-77391

A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This a

4.3
CVE-2026-78280

Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

4.3
CVE-2026-82544

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of th

4.2
CVE-2026-57306

A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier al

4.2
CVE-2026-70434

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to c

4.2
CVE-2026-18165

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin val

4.2
CVE-2026-74867

SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cookie authentication bra

4.2
CVE-2026-15046

The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites

Frequently Asked Questions

What is CWE-352?

CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-352?

There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.

How can I protect against CWE-352 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.

Detect CWE-352 Vulnerabilities

CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.

Get Started