CWE-352— Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.— MITRE CWE catalog
9,377 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-352page 24 of 188
- CVE-2016-10902HIGHCVSS 8.8EG 8.82019-08-21
The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
- CVE-2016-10903HIGHCVSS 8.8EG 8.82019-08-21
The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
- CVE-2016-10914HIGHCVSS 8.8EG 8.82019-08-20
The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
- CVE-2016-10915HIGHCVSS 8.8EG 8.82019-08-20
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
- CVE-2016-10918HIGHCVSS 8.8EG 8.82019-08-22
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
- CVE-2016-10938MEDIUMCVSS 6.5EG 6.52019-09-13
The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
- CVE-2016-10944HIGHCVSS 8.8EG 8.82019-09-13
The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
- CVE-2016-10945HIGHCVSS 8.8EG 8.82019-09-13
The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
- CVE-2016-10946HIGHCVSS 8.8EG 8.82019-09-13
The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
- CVE-2016-10962MEDIUMCVSS 6.5EG 6.52019-09-16
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
- CVE-2016-10974HIGHCVSS 8.8EG 8.82019-09-17
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.
- CVE-2016-10978HIGHCVSS 8.8EG 8.82019-09-17
The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.
- CVE-2016-10982HIGHCVSS 8.8EG 8.82019-09-17
The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
- CVE-2016-10989HIGHCVSS 8.8EG 8.82019-09-17
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
- CVE-2016-10997MEDIUMCVSS 6.5EG 6.52019-09-20
The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.
- CVE-2016-11015MEDIUMCVSS 6.5EG 6.52019-10-16
NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter.BlackList.1.URL parameter.
- CVE-2016-11055MEDIUMCVSS 4.3EG 4.32020-04-28
Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 before 2017-01-11, D500 before 2017-01-11, DST6501 before 2017-01-11, JNR1010v1 before 2017-01-11, JWNR2000Tv3 before 2017-0…
- CVE-2016-11084MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
- CVE-2016-11085MEDIUMCVSS 6.5EG 6.52020-08-16
php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.
- CVE-2016-1134HIGHCVSS 8.8EG 8.82016-01-22
Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmwa…
- CVE-2016-1139HIGHCVSS 7.5EG 7.52016-01-30
Cross-site request forgery (CSRF) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2016-1151HIGHCVSS 8.8EG 8.82016-02-17
Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users.
- CVE-2016-1158HIGHCVSS 8.8EG 8.82016-03-03
Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of administrators for requests that perform administrative functions.
- CVE-2016-1161HIGHCVSS 8.0EG 8.02017-04-20
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).
- CVE-2016-1167HIGHCVSS 8.8EG 8.82016-04-01
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authentication of arbitrary users.
- CVE-2016-1168HIGHCVSS 8.8EG 8.82016-04-01
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hijack the authentication of arbitrary users.
- CVE-2016-1170HIGHCVSS 8.8EG 8.82016-04-06
Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to hijack the authentication of administrators.
- CVE-2016-1172HIGHCVSS 8.8EG 8.82016-04-06
Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.
- CVE-2016-1174HIGHCVSS 8.8EG 8.82016-04-06
Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.
- CVE-2016-1175MEDIUMCVSS 4.3EG 4.32016-04-05
Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users.
- CVE-2016-1201HIGHCVSS 8.8EG 8.82016-04-30
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the authentication of administrators.
- CVE-2016-1228HIGHCVSS 8.8EG 8.82016-07-03
Cross-site request forgery (CSRF) vulnerability on NTT EAST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1006 and earlier and NTT WEST Hikari Denwa routers with firmware PR-400MI, RT-400MI, and RV-440MI 07.00.1…
- CVE-2016-1261HIGHCVSS 8.8EG 8.82017-10-13
J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).
- CVE-2016-1265CRITICALCVSS 9.8EG 9.82017-10-13
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentia…
- CVE-2016-1448HIGHCVSS 8.8EG 8.82016-07-17
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706.
- CVE-2016-1470HIGHCVSS 8.8EG 8.82016-09-02
Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCu…
- CVE-2016-15005HIGHCVSS 8.8EG 8.82022-12-27
CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an attacker to predict values and bypass CSRF protections with relatively few requests.
- CVE-2016-15009HIGHCVSS 3.5EG 8.82023-01-05
A vulnerability classified as problematic has been found in OpenACS bug-tracker. Affected is an unknown function of the file lib/nav-bar.adp of the component Search. The manipulation leads to cross-site request forgery. It is possible to l…
- CVE-2016-1607HIGHCVSS 7.2EG 7.22016-08-01
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote attackers to hijack the authentication of administrators, as demonstrated by reconfiguring …
- CVE-2016-20028MEDIUMCVSS 4.3EG 4.32026-03-16
ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious websites. Attackers can craft HTTP requests that add s…
- CVE-2016-20034HIGHCVSS 8.0EG 8.82026-03-16
Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit …
- CVE-2016-20035MEDIUMCVSS 4.3EG 5.32026-03-16
Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a maliciou…
- CVE-2016-20051MEDIUMCVSS 4.3EG 5.32026-04-04
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visi…
- CVE-2016-20053MEDIUMCVSS 6.5EG 6.52026-04-04
Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting malicious pages. Attackers can craft HTM…
- CVE-2016-20054MEDIUMCVSS 4.3EG 4.32026-04-04
Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administrators into submitting requests to admin…
- CVE-2016-20067MEDIUMCVSS 4.3EG 4.32026-06-15
WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML pages that execute unwanted poll operat…
- CVE-2016-20074MEDIUMCVSS 4.3EG 4.32026-06-15
WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into subm…
- CVE-2016-20083MEDIUMCVSS 5.3EG 5.32026-06-15
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in adm…
- CVE-2016-2082HIGHCVSS 8.8EG 8.82016-07-03
Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
- CVE-2016-2157HIGHCVSS 8.8EG 8.82016-05-22
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authe…
Map vulnerabilities like CWE-352 to your infrastructure
EchelonGraph correlates every CVE — across CWE-352 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →