Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4750

4750 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-41425 Authlib: Cross-site request forging when using cache — authlib 5.4 Medium2026-04-24
CVE-2026-3565 Taqnix <= 1.0.3 - Cross-Site Request Forgery to Account Deletion via 'taqnix_delete_my_account' AJAX Action — Taqnix 4.3 Medium2026-04-24
CVE-2026-41317 Frappe Press has an unsafe HTTP method / CSRF-adjacent issue on API secret generation — press 8.8AIHighAI2026-04-24
CVE-2026-27841 SenseLive X3050 Cross-Site request forgery — X3050 8.1 High2026-04-24
CVE-2026-41347 OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints — OpenClaw 7.1 High2026-04-23
CVE-2026-40471 Hackage CSRF vulnerability 9.6 Critical2026-04-23
CVE-2026-4922 Cross-Site Request Forgery (CSRF) in GitLab — GitLab 8.1 High2026-04-22
CVE-2025-58922 WordPress Avada theme < 7.13.2 - Cross Site Request Forgery (CSRF) vulnerability — Avada 4.3 Medium2026-04-22
CVE-2026-4138 DX Unanswered Comments <= 1.7 - Cross-Site Request Forgery via Settings Update — DX Unanswered Comments 4.3 Medium2026-04-22
CVE-2026-6294 Google PageRank Display <= 1.4 - Cross-Site Request Forgery to Settings Update via Settings Page — Google PageRank Display 4.3 Medium2026-04-22
CVE-2026-4121 Kcaptcha <= 1.0.1 - Cross-Site Request Forgery to Settings Update — Kcaptcha 4.3 Medium2026-04-22
CVE-2026-4090 Inquiry cart <= 3.4.2 - Cross-Site Request Forgery via Settings Form — Inquiry cart 6.1 Medium2026-04-22
CVE-2026-4118 Call To Action Plugin <= 3.1.3 - Cross-Site Request Forgery via Settings Update — Call To Action Plugin 4.3 Medium2026-04-22
CVE-2026-4139 mCatFilter <= 0.5.2 - Cross-Site Request Forgery via compute_post() Function — mCatFilter 4.3 Medium2026-04-22
CVE-2026-4140 Ni WooCommerce Order Export <= 3.1.6 - Cross-Site Request Forgery to Settings Update via ni_order_export_action AJAX Action — Ni WooCommerce Order Export 4.3 Medium2026-04-22
CVE-2026-6396 Fast & Fancy Filter – 3F <= 1.2.2 - Cross-Site Request Forgery to Settings Modification via fff_save_settins AJAX Action — Fast & Fancy Filter – 3F 4.3 Medium2026-04-22
CVE-2026-4133 TextP2P Texting Widget <= 1.7 - Cross-Site Request Forgery to Settings Update — TextP2P Texting Widget 4.3 Medium2026-04-22
CVE-2026-4131 WP Responsive Popup + Optin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'wpo_image_url' Parameter — WP Responsive Popup + Optin 6.1 Medium2026-04-22
CVE-2026-40929 WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators — AVideo 5.4 Medium2026-04-21
CVE-2026-40928 AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion — AVideo 5.4 Medium2026-04-21
CVE-2026-40926 WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script) — AVideo 7.1 High2026-04-21
CVE-2026-40925 WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials — AVideo 8.3 High2026-04-21
CVE-2026-40883 goshs: CSRF in state-changing GET routes enables authenticated file deletion and directory creation — goshs 8.1AIHighAI2026-04-21
CVE-2026-41194 FreeScout's Mailbox OAuth disconnect uses a state-changing GET and is CSRFable — freescout 5.4 Medium2026-04-21
CVE-2026-6589 ComfyUI server.py create_origin_only_middleware cross-site request forgery — ComfyUI 4.3 Medium2026-04-20
CVE-2026-40948 Apache Airflow Providers Keycloak: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager — Apache Airflow Providers Keycloak 7.3AIHighAI2026-04-18
CVE-2026-40581 ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion — CRM 8.1 High2026-04-17
CVE-2026-40458 Cross-Site Request Forgery in PAC4J — PAC4J 6.5AIMediumAI2026-04-17
CVE-2026-6451 CMS für Motorrad Werkstätten <= 1.0.0 - Cross-Site Request Forgery — Plugin: CMS für Motorrad Werkstätten 4.3 Medium2026-04-17
CVE-2025-15635 WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Request Forgery (CSRF) vulnerability — Smart Online Order for Clover 4.3 Medium2026-04-15

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4750 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.