CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,382 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 95 of 188
- CVE-2023-28335HIGHCVSS 8.8EG 8.82023-03-23
The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
- CVE-2023-28361MEDIUMCVSS 6.5EG 6.52023-05-11
A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud…
- CVE-2023-28419MEDIUMCVSS 5.4EG 5.42023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions.
- CVE-2023-2842HIGHCVSS 8.1EG 8.12023-06-27
The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack
- CVE-2023-28420MEDIUMCVSS 5.4EG 5.42023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Leo Caseiro Custom Options Plus plugin <= 1.8.1 versions.
- CVE-2023-28495MEDIUMCVSS 4.3EG 4.32023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions.
- CVE-2023-28497MEDIUMCVSS 5.4EG 5.42023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery LITE plugin <= 1.7.6 versions.
- CVE-2023-28498MEDIUMCVSS 4.3EG 4.32023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions.
- CVE-2023-28618MEDIUMCVSS 5.4EG 5.42023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Enhanced Plugin Admin plugin <= 1.16 versions.
- CVE-2023-28671MEDIUMCVSS 4.3EG 4.32023-04-02
A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another m…
- CVE-2023-28674HIGHCVSS 8.8EG 8.82023-04-02
A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a previously configured Octoperf server using attacker-specified credentials.
- CVE-2023-28676HIGHCVSS 8.8EG 8.82023-04-02
A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based on a Freestyle project, potentially leading to remote code execution (RCE).
- CVE-2023-28688MEDIUMCVSS 5.4EG 5.42024-12-09
Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation Swatches: from n/a through 1.2.7.
- CVE-2023-28694MEDIUMCVSS 5.4EG 5.42023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Wbcom Designs Wbcom Designs – BuddyPress Activity Social Share plugin <= 3.5.0 versions.
- CVE-2023-28696MEDIUMCVSS 4.3EG 4.32023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Harish Chouhan, Themeist I Recommend This allows Cross Site Request Forgery.This issue affects I Recommend This: from n/a through 3.9.0.
- CVE-2023-28718HIGHCVSS 7.1EG 8.02023-03-28
Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to perform certain actions with administrative privileges if a l…
- CVE-2023-28747MEDIUMCVSS 5.4EG 5.42023-11-22
Cross-Site Request Forgery (CSRF) vulnerability in codeboxr CBX Currency Converter plugin <= 3.0.3 versions.
- CVE-2023-28749MEDIUMCVSS 4.3EG 4.32023-11-22
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.
- CVE-2023-28780MEDIUMCVSS 6.5EG 6.52023-11-18
Cross-Site Request Forgery (CSRF) vulnerability in Yoast Yoast Local Premium.This issue affects Yoast Local Premium: from n/a through 14.8.
- CVE-2023-28791MEDIUMCVSS 4.3EG 4.32023-10-06
Cross-Site Request Forgery (CSRF) vulnerability in Gangesh Matta Simple Org Chart plugin <= 2.3.4 versions.
- CVE-2023-28848MEDIUMCVSS 4.8EG 4.82023-04-04
user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expec…
- CVE-2023-2891MEDIUMCVSS 6.5EG 6.52023-06-09
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_delete_product function. This makes it possible f…
- CVE-2023-2892MEDIUMCVSS 6.5EG 6.52023-06-09
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_delete_product function. This makes it possi…
- CVE-2023-2893MEDIUMCVSS 4.3EG 4.32023-06-09
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_deactivate_product function. This makes it possib…
- CVE-2023-28930MEDIUMCVSS 4.3EG 4.32023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Robin Phillips Mobile Banner plugin <= 1.5 versions.
- CVE-2023-2894MEDIUMCVSS 4.3EG 4.32023-06-09
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_deactivate_product function. This makes it p…
- CVE-2023-28949MEDIUMCVSS 6.5EG 6.52024-03-01
IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID:…
- CVE-2023-2895MEDIUMCVSS 4.3EG 4.32023-06-09
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_bulk_activate_product function. This makes it pos…
- CVE-2023-2896MEDIUMCVSS 4.3EG 4.32023-06-09
The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8. This is due to missing or incorrect nonce validation on the process_duplicate_product function. This makes it possibl…
- CVE-2023-28986MEDIUMCVSS 5.4EG 5.42023-07-10
Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager plugin <= 2.9.20 versions.
- CVE-2023-28987MEDIUMCVSS 4.3EG 4.32023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.
- CVE-2023-28989MEDIUMCVSS 4.3EG 4.32023-07-10
Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions.
- CVE-2023-28995MEDIUMCVSS 5.4EG 5.42023-07-10
Cross-Site Request Forgery (CSRF) vulnerability in Keith Solomon Configurable Tag Cloud (CTC) plugin <= 5.2 versions.
- CVE-2023-29003HIGHCVSS 8.8EG 8.82023-04-04
SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit pro…
- CVE-2023-29008HIGHCVSS 8.8EG 8.82023-04-06
The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request fo…
- CVE-2023-29020MEDIUMCVSS 6.5EG 6.52023-04-21
@fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by the `@fastify/csrf-protection` library, when combined with `@fastify/passport` in affecte…
- CVE-2023-2919MEDIUMCVSS 4.3EG 4.32024-09-10
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or incorrect nonce validation on the 'addon_enable_disable' function. This makes it possible for…
- CVE-2023-29213CRITICALCVSS 9.0EG 9.02023-04-17
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:xwiki-platform-logging-ui` it is possible to trick a user with programming rights into vis…
- CVE-2023-29235MEDIUMCVSS 5.4EG 5.42023-10-06
Cross-Site Request Forgery (CSRF) vulnerability in Fugu Maintenance Switch plugin <= 1.5.2 versions.
- CVE-2023-29238MEDIUMCVSS 4.3EG 4.32023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in Whydonate Whydonate – FREE Donate button – Crowdfunding – Fundraising plugin <= 3.12.15 versions.
- CVE-2023-29425MEDIUMCVSS 5.4EG 5.42023-11-12
Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.
- CVE-2023-29426HIGHCVSS 4.3EG 8.82023-11-10
Cross-Site Request Forgery (CSRF) vulnerability in Robert Schulz (sprd.Net AG) Spreadshop plugin <= 1.6.5 versions.
- CVE-2023-29428HIGHCVSS 5.3EG 8.82023-11-10
Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin <= 1.1.3 versions.
- CVE-2023-29440HIGHCVSS 4.3EG 8.82023-11-10
Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board plugin <= 2.10.3 versions.
- CVE-2023-29815HIGHCVSS 8.8EG 8.82023-04-28
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
- CVE-2023-3011MEDIUMCVSS 6.5EG 6.52023-07-12
The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5. This is due to missing or incorrect nonce validation on the arm_check_user_cap function. This makes it possible for unau…
- CVE-2023-3029MEDIUMCVSS 4.3EG 4.32023-06-01
A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. This vulnerability affects unknown code of the file /note/index/delete. The manipulation of the argument id leads to cros…
- CVE-2023-30474HIGHCVSS 4.3EG 8.82023-04-16
Cross-Site Request Forgery (CSRF) vulnerability in Kilian Evang Ultimate Noindex Nofollow Tool II plugin <= 1.3 versions.
- CVE-2023-30478HIGHCVSS 5.4EG 8.82023-11-10
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
- CVE-2023-30484MEDIUMCVSS 4.3EG 4.32023-05-25
Cross-Site Request Forgery (CSRF) vulnerability in uPress Enable Accessibility plugin <= 1.4 versions.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →