CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,376 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 13 of 188
- CVE-2013-2108MEDIUMCVSS 5.4EG 5.42020-02-10
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
- CVE-2013-2109HIGHCVSS 8.8EG 8.82020-02-10
WordPress plugin wp-cleanfix has Remote Code Execution
- CVE-2013-2158MEDIUMCVSS v2 6.8EG 6.82013-07-01
Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2013-2305MEDIUMCVSS v2 6.8EG 6.82013-04-25
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attackers to hijack the authentication of arbitrary users for req…
- CVE-2013-2628MEDIUMCVSS v2 6.8EG 6.82013-12-21
Multiple cross-site request forgery (CSRF) vulnerabilities in action.php in Leed (Light Feed), possibly before 1.5 Stable, allow remote attackers to hijack the authentication of administrators for unspecified requests, related to the lack …
- CVE-2013-2645HIGHCVSS v2 9.3EG 9.32014-10-06
Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to hijack the authentication of administrators for requests that (1) enable FTP access (aka…
- CVE-2013-2692MEDIUMCVSS v2 6.8EG 6.82014-05-13
Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users.
- CVE-2013-2693MEDIUMCVSS v2 6.8EG 6.82014-04-10
Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unspeci…
- CVE-2013-2696MEDIUMCVSS v2 6.8EG 6.82013-04-25
Cross-site request forgery (CSRF) vulnerability in the All in One Webmaster plugin before 8.2.4 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- CVE-2013-2697MEDIUMCVSS v2 6.8EG 6.82013-04-19
Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- CVE-2013-2698MEDIUMCVSS v2 6.8EG 6.82014-05-27
Cross-site request forgery (CSRF) vulnerability in the Calendar plugin before 1.3.3 for WordPress allows remote attackers to hijack the authentication of users for requests that add a calendar entry via unspecified vectors.
- CVE-2013-2699MEDIUMCVSS v2 6.8EG 6.82014-04-10
Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for requests that deactivate a plugin via unspecified vectors.
- CVE-2013-2700MEDIUMCVSS v2 6.8EG 6.82014-05-14
Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that add or edit an ad…
- CVE-2013-2701MEDIUMCVSS v2 6.8EG 6.82013-11-01
Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vector…
- CVE-2013-2702MEDIUMCVSS v2 6.8EG 6.82013-05-05
Cross-site request forgery (CSRF) vulnerability in the Easy AdSense Lite plugin before 6.10 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.
- CVE-2013-2703MEDIUMCVSS v2 6.8EG 6.82013-05-05
Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings.
- CVE-2013-2704MEDIUMCVSS v2 6.8EG 6.82013-07-12
Cross-site request forgery (CSRF) vulnerability in the Dropdown Menu Widget plugin 1.9.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
- CVE-2013-2705MEDIUMCVSS v2 6.8EG 6.82014-05-13
Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.
- CVE-2013-2706MEDIUMCVSS v2 6.8EG 6.82014-04-11
Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
- CVE-2013-2707MEDIUMCVSS v2 6.8EG 6.82013-05-10
Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.
- CVE-2013-2708MEDIUMCVSS v2 6.8EG 6.82014-04-11
Cross-site request forgery (CSRF) vulnerability in the Content Slide plugin 1.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
- CVE-2013-2709MEDIUMCVSS v2 6.8EG 6.82013-04-26
Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
- CVE-2013-2710MEDIUMCVSS v2 6.8EG 6.82014-06-02
Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) a…
- CVE-2013-2713MEDIUMCVSS v2 6.8EG 6.82014-05-23
Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.
- CVE-2013-2752MEDIUMCVSS v2 6.8EG 6.82013-12-12
Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to hijack the authentication of users.
- CVE-2013-2754MEDIUMCVSS v2 6.8EG 6.82014-03-11
Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/…
- CVE-2013-2778HIGHCVSS v2 7.5EG 7.52013-04-09
Cross-site request forgery (CSRF) vulnerability in addressbook/register/delete_user.php in PHP Address Book 8.2.5 allows remote attackers to hijack the authentication of administrators for requests that delete accounts, a different vulnera…
- CVE-2013-2980MEDIUMCVSS v2 6.8EG 6.82013-06-17
Cross-site request forgery (CSRF) vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to hijack the authentication of arbitrary users for requests that access monitored database information.
- CVE-2013-3029MEDIUMCVSS v2 6.8EG 6.82013-08-21
Cross-site request forgery (CSRF) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.1 allows remote attackers to hijack …
- CVE-2013-3068MEDIUMCVSS v2 6.8EG 6.82014-09-29
Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords and modify remote management ports.
- CVE-2013-3083MEDIUMCVSS v2 6.8EG 6.82014-09-29
Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attackers to hijack the authentication of administrators for requests that open the remote management interface on arbitrary…
- CVE-2013-3086MEDIUMCVSS v2 6.8EG 6.82014-09-29
Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hijack the authentication of administrators for requests that change configuration settings including passwords and remote…
- CVE-2013-3089MEDIUMCVSS v2 6.8EG 6.82014-09-29
Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.
- CVE-2013-3093HIGHCVSS 8.8EG 8.82020-01-28
ASUS RT-N56U devices allow CSRF.
- CVE-2013-3095MEDIUMCVSS v2 6.8EG 6.82013-11-20
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator…
- CVE-2013-3098MEDIUMCVSS v2 6.8EG 6.82014-02-04
Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a…
- CVE-2013-3250MEDIUMCVSS v2 6.8EG 6.82013-06-21
Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.
- CVE-2013-3251MEDIUMCVSS v2 6.8EG 6.82014-04-10
Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vecto…
- CVE-2013-3252MEDIUMCVSS v2 6.8EG 6.82014-04-10
Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings …
- CVE-2013-3253MEDIUMCVSS v2 6.8EG 6.82013-08-09
Cross-site request forgery (CSRF) vulnerability in admin/setting.php in the Xhanch - My Twitter plugin before 2.7.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change unspecified s…
- CVE-2013-3256MEDIUMCVSS v2 6.8EG 6.82013-08-08
Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows remote attackers to hijack the authentication of users for requests that "manipulate plugin settings."
- CVE-2013-3257MEDIUMCVSS v2 6.8EG 6.82014-06-02
Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors.
- CVE-2013-3258MEDIUMCVSS v2 6.8EG 6.82014-06-02
Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors.
- CVE-2013-3269MEDIUMCVSS v2 6.8EG 6.82013-04-25
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0 allows remote attackers to hijack the authentication of arbitrary users for requests that change mobile passwords, a different vulnerability…
- CVE-2013-3312HIGHCVSS 8.8EG 8.82019-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, a…
- CVE-2013-3366HIGHCVSS 8.8EG 8.82019-11-13
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
- CVE-2013-3392MEDIUMCVSS v2 4.3EG 4.32013-06-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco WebEx Social allow remote attackers to hijack the authentication of arbitrary users via unspecified vectors, aka Bug IDs CSCuh10405 and CSCuh10355.
- CVE-2013-3395MEDIUMCVSS v2 6.8EG 6.82013-07-02
Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote atta…
- CVE-2013-3397MEDIUMCVSS v2 6.8EG 6.82013-06-26
Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability component in Cisco Unified Communications Manager (CUCM) allows remote attackers to hijack the authentication of arbitrary users for requests that perform Unifie…
- CVE-2013-3420MEDIUMCVSS v2 6.8EG 6.82013-07-18
Cross-site request forgery (CSRF) vulnerability in the web framework on the Cisco Identity Services Engine (ISE) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh25506.
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →