The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields
IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malic
The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to
The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX acti
The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could all
The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers
In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not
In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `st
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials f
The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make
Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attack
The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could
The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admi
The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which
The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which
The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, whi
The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which cou
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re
MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious pa
Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vul
Cross-Site Request Forgery (CSRF) vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) feature
Cross-Site Request Forgery (CSRF) vulnerability in Latepoint LatePoint allows Cross Site Request Forgery.This issue affe
A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` fi
IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious
Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.
wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily d
Zimbra GraphQL Cross-Site Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attacke
IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an att
Cross-Site Request Forgery (CSRF) vulnerability in ilGhera Woocommerce Support System allows Cross Site Request Forgery.
The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w
Cross-Site Request Forgery (CSRF) vulnerability in codehandling Youtube Video Grid youmax-channel-embeds-for-youtube-bus
Cross-Site Request Forgery (CSRF) vulnerability in Posti Posti Shipping posti-shipping allows Cross Site Request Forgery
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a th
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in a
Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/sys_cache_up.php.
Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet S
Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data v
Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Fo
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mu
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mud
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mud
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t
Frequently Asked Questions
What is CWE-352?
CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-352?
There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.
How can I protect against CWE-352 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.
Detect CWE-352 Vulnerabilities
CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.
Get Started