Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4754

4754 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0660 Formidable Forms <= 6.7.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder 6.1 Medium2024-02-05
CVE-2024-0790 WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery — WOLF – WordPress Posts Bulk Editor and Manager Professional 5.4 Medium2024-02-05
CVE-2024-0796 Active Products Tables for WooCommerce. Professional products tables for WooCommerce store <= 1.0.6.1 - Cross-Site Request Forgery — Active Products Tables for WooCommerce. Use constructor to create tables 4.3 Medium2024-02-05
CVE-2024-0859 Affiliates Manager <= 2.9.34 - Cross-Site Request Forgery — Affiliates Manager 4.3 Medium2024-02-05
CVE-2024-23831 Privilege escalation through CSRF attack on 'setup.pl' — LedgerSMB 7.5 High2024-02-02
CVE-2023-6676 Cross Site Request Forgery in National Keep's CyberMath — CyberMath 8.8 High2024-02-02
CVE-2024-1162 Orbit Fox by ThemeIsle <= 2.10.29 - Cross-Site Request Forgery — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More 4.3 Medium2024-02-02
CVE-2024-22136 WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF) — Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder 4.3 Medium2024-01-31
CVE-2024-22140 WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Request Forgery (CSRF) — Profile Builder Pro 8.8 High2024-01-31
CVE-2024-22143 WordPress WP Spell Check Plugin <= 9.17 is vulnerable to Cross Site Request Forgery (CSRF) — WP Spell Check 5.4 Medium2024-01-31
CVE-2024-22285 WordPress Frontpage Manager Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) — Frontpage Manager 5.4 Medium2024-01-31
CVE-2024-22291 WordPress Browser Theme Color Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) — Browser Theme Color 4.3 Medium2024-01-31
CVE-2024-22304 WordPress FreshMail For WordPress Plugin <= 2.3.2 is vulnerable to Cross Site Request Forgery (CSRF) — FreshMail For WordPress 5.4 Medium2024-01-31
CVE-2024-22287 WordPress Better Anchor Links Plugin <= 1.7.5 is vulnerable to Cross Site Request Forgery (CSRF) — Better Anchor Links 7.1 High2024-01-31
CVE-2024-22290 WordPress Custom Dashboard Widgets Plugin <= 1.3.1 is vulnerable to Cross Site Request Forgery (CSRF) — Custom Dashboard Widgets 7.1 High2024-01-31
CVE-2024-0880 Qidianbang qdbcrm Password Reset cross-site request forgery — qdbcrm 4.3 Medium2024-01-25
CVE-2024-0624 Paid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders Update — Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions 5.3 Medium2024-01-25
CVE-2024-0623 VK Block Patterns <= 1.31.1.1 - Cross-Site Request Forgery — VK Block Patterns 4.3 Medium2024-01-20
CVE-2023-47718 IBM Maximo Asset Management cross-site request forgery — Maximo Asset Management 4.3 Medium2024-01-19
CVE-2024-22424 Cross-Site Request Forgery (CSRF) in github.com/argoproj/argo-cd — argo-cd 8.4 High2024-01-19
CVE-2024-22416 Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation — pyload 9.7 Critical2024-01-17
CVE-2022-41990 WordPress 3D Tag Cloud Plugin <= 3.8 is vulnerable to Cross Site Request Forgery (CSRF) — 3D Tag Cloud 7.1 High2024-01-17
CVE-2024-0555 Cross-Site Request Forgery (CSRF) vulnerability on WIC1200 — WIC1200 4.6 Medium2024-01-16
CVE-2024-0522 Allegro RomPager HTTP POST Request cross-site request forgery — RomPager 4.3 Medium2024-01-14
CVE-2023-6242 EventON - WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Cross-Site Request Forgery via evo_eventpost_update_meta — EventON – Events Calendar 6.5 Medium2024-01-11
CVE-2023-6244 EventON - WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) - Cross-Site Request Forgery via save_virtual_event_settings — EventON – Events Calendar 6.5 Medium2024-01-11
CVE-2023-4247 GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin deactivation — GiveWP – Donation Plugin and Fundraising Platform 5.4 Medium2024-01-11
CVE-2023-4246 GiveWP <= 2.33.3 - Cross-Site Request Forgery to plugin installation — GiveWP – Donation Plugin and Fundraising Platform 4.3 Medium2024-01-11
CVE-2023-7048 My Sticky Bar <= 2.6.6 - Cross-Site Request Forgery to Sensitive Information Exposure — My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) 3.1 Low2024-01-11
CVE-2023-4248 GiveWP <= 2.33.3 - Cross-Site Request Forgery to Stripe Integration Deletion — GiveWP – Donation Plugin and Fundraising Platform 5.4 Medium2024-01-11

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4754 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.