Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-352

MITRE ↗

Cross-Site Request Forgery (CSRF)

134
CRITICAL
3,349
HIGH
4,754
MEDIUM
98
LOW
8,392 CVEs · Page 5/168
7.5
CVE-2026-16262

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating

7.4
CVE-2026-57723

Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal.

7.4
CVE-2026-48551

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a sel

7.4
CVE-2026-66635

Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.

7.3
CVE-2026-25649

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat

7.3
CVE-2026-50132

Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a publi

7.3
CVE-2026-65947

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

7.3
CVE-2026-72658

Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62

7.1
CVE-2025-14615

The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request

7.1
CVE-2026-22355

Cross-Site Request Forgery (CSRF) vulnerability in gregmolnar Simple XML Sitemap simple-xml-sitemap allows Stored XSS.Th

7.1
CVE-2026-26317

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin

7.1
CVE-2026-28477

OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login f

7.1
CVE-2026-28281

InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF token

7.1
CVE-2026-22323

A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick

7.1
CVE-2025-55045

The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information

7.1
CVE-2024-32537

Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This

7.1
CVE-2026-33252

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted

7.1
CVE-2026-39671

Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fe

7.1
CVE-2019-25693

ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL q

7.1
CVE-2026-40926

WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/cat

7.1
CVE-2026-41347

OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mod

7.1
CVE-2026-45430

The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the au

7.1
CVE-2026-41074

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Si

7.1
CVE-2026-39436

Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affe

7.1
CVE-2026-49396

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be

7.1
CVE-2026-57757

Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.

7.1
CVE-2026-57758

Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

7.1
CVE-2026-57761

Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

7.1
CVE-2026-61956

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allo

7.1
CVE-2026-62443

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

7.1
CVE-2026-57626

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailP

7.1
CVE-2026-65488

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

7.1
CVE-2026-65539

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

7.1
CVE-2026-65540

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

7.1
CVE-2026-14234

The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowin

7.1
CVE-2026-14239

The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken fro

7.1
CVE-2026-28172

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

7.1
CVE-2026-13365

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to e

7.1
CVE-2026-19650

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.

7.1
CVE-2026-58003

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php

6.8
CVE-2025-61547

Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 1

6.8
CVE-2026-2994

Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configu

6.8
CVE-2026-28741

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF toke

6.8
CVE-2026-73847

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant exec

6.5
CVE-2026-22030

React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through

6.5
CVE-2021-47754

Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settin

6.5
CVE-2021-47830

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can cra

6.5
CVE-2025-70899

PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative form

6.5
CVE-2026-24666

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,

6.5
CVE-2026-24434

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative fun

Frequently Asked Questions

What is CWE-352?

CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-352?

There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.

How can I protect against CWE-352 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.

Detect CWE-352 Vulnerabilities

CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.

Get Started