WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSavePhoto.php is a legac
Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could b
A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: So
Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's informa
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through
NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage
A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attac
A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allow
A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and ea
A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect
The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a
grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASec
Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventList
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it veri
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Suppo
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Sup
Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Su
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Suppor
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Admi
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allow
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta
The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque
Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm
The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentica
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager
phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / b
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login
AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that all
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its setti
SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attacker
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attac
b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account deta
Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without us
GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attac
Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings
birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows att
Sickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by s
Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attacke
Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administr
Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface.
Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized a
Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user
Frequently Asked Questions
What is CWE-352?
CWE-352 (Cross-Site Request Forgery (CSRF)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-352?
There are 10,808 CVE records associated with CWE-352 in our database. Of these, 134 are critical severity, 3349 are high severity, and 4754 are medium severity.
How can I protect against CWE-352 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-352 using AI-powered security agents.
Detect CWE-352 Vulnerabilities
CyberStrike's AI agents automatically detect cross-site request forgery (csrf) vulnerabilities across your infrastructure.
Get Started