Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-352

MITRE ↗

Cross-Site Request Forgery (CSRF)

134
CRITICAL
3,349
HIGH
4,754
MEDIUM
98
LOW
8,392 CVEs · Page 4/168
8.1
CVE-2026-28761

Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 a

8.1
CVE-2026-6455

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary F

8.1
CVE-2026-6075

The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl

8.1
CVE-2026-55744

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage

8.1
CVE-2026-43735

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS

8.1
CVE-2026-57751

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

8.1
CVE-2026-12740

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 bu

8.1
CVE-2026-12746

Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The

8.1
CVE-2026-59713

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without

8.1
CVE-2026-38057

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot en

8.1
CVE-2026-58476

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that al

8.1
CVE-2026-65757

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - T

8.1
CVE-2026-12586

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset

8.1
CVE-2026-7444

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and

8.1
CVE-2026-73482

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The admin

8.1
CVE-2026-17069

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

8.1
CVE-2026-81273

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

8.0
CVE-2025-59891

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.

8.0
CVE-2025-59892

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.

8.0
CVE-2025-59893

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.

8.0
CVE-2025-59894

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.

8.0
CVE-2025-55041

MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc

8.0
CVE-2025-11954

Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S

8.0
CVE-2026-48612

Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow an

8.0
CVE-2026-46787

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup

8.0
CVE-2026-46894

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versi

8.0
CVE-2026-34171

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.

8.0
CVE-2026-60643

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.0
CVE-2026-60646

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-60648

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-60650

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).

8.0
CVE-2026-63265

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension

8.0
CVE-2026-14951

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface u

7.9
CVE-2026-35266

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. D

7.8
CVE-2026-28201

An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allo

7.7
CVE-2026-72849

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows

7.6
CVE-2026-60642

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.6
CVE-2026-60886

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor

7.6
CVE-2026-61132

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th

7.6
CVE-2026-55532

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin

7.5
CVE-2026-3589

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allo

7.5
CVE-2026-29784

Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /sessio

7.5
CVE-2026-34896

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows C

7.5
CVE-2026-34904

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request

7.5
CVE-2026-41317

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-

7.5
CVE-2026-11265

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross

7.5
CVE-2026-46955

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions

7.5
CVE-2026-52100

Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e

7.5
CVE-2026-60658

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

7.5
CVE-2026-7326

A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows

Frequently Asked Questions

What is CWE-352?

CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-352?

There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.

How can I protect against CWE-352 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.

Detect CWE-352 Vulnerabilities

CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.

Get Started