Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4753

4753 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-1871 YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Reset — YourChannel: Everything you want in a YouTube plugin. 5.4 Medium2023-04-05
CVE-2023-1870 YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Language Translation Update — YourChannel: Everything you want in a YouTube plugin. 4.3 Medium2023-04-05
CVE-2023-1867 YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Settings Change — YourChannel: Everything you want in a YouTube plugin. 5.4 Medium2023-04-05
CVE-2023-1866 YourChannel <= 1.2.4 - Cross-Site Request Forgery to Plugin Channel Reset — YourChannel: Everything you want in a YouTube plugin. 5.4 Medium2023-04-05
CVE-2023-29003 SvelteKit has Insufficient Cross-Site Request Forgery Protection — kit 8.8 High2023-04-04
CVE-2023-28848 CSRF protection on user_oidc login returned the expected token in case of an error — security-advisories 4.8 Medium2023-04-04
CVE-2022-41633 WordPress Community by PeepSo Plugin <= 6.0.2.0 is vulnerable to Cross Site Request Forgery (CSRF) — Community by PeepSo – Social Network, Membership, Registration, User Profiles 5.4 Medium2023-04-04
CVE-2023-23861 WordPress GMAce Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF) — GMAce 5.4 Medium2023-03-29
CVE-2022-38077 WordPress Popup Anything Plugin <= 2.2.1 is vulnerable to Cross Site Request Forgery (CSRF) — Popup Anything – A Marketing Popup and Lead Generation Conversions 4.3 Medium2023-03-29
CVE-2023-1509 GMAce <= 1.5.2 - Cross-Site Request Forgery to Arbitrary File Modification (Creation/Overwrite/Deletion) — GMAce 8.8 High2023-03-29
CVE-2022-30705 WordPress WordPress Ping Optimizer Plugin <= 2.35.1.2.3 is vulnerable to Cross Site Request Forgery (CSRF) — WordPress Ping Optimizer 5.4 Medium2023-03-27
CVE-2023-20113 Cisco SD-WAN vManage Software Cross-Site Request Forgery Vulnerability — Cisco SD-WAN vManage 6.5 Medium2023-03-23
CVE-2023-28335 Moodle: csrf risk in resetting all templates of a database activity 8.8 -2023-03-23
CVE-2023-0870 Form Can Be Manipulated with Cross-Site Request Forgery (CSRF) — Meridian 8.1 High2023-03-22
CVE-2023-23721 WordPress Admin Log Plugin <= 1.50 is vulnerable to Cross Site Request Forgery (CSRF) — Admin Log 4.3 Medium2023-03-20
CVE-2023-22678 WordPress Superior FAQ Plugin <= 1.0.2 is vulnerable to Cross Site Request Forgery (CSRF) — Superior FAQ 5.4 Medium2023-03-20
CVE-2023-22681 WordPress Online Exam Software : eExamhall Plugin <= 4.0 is vulnerable to Cross Site Request Forgery (CSRF) — Online Exam Software : eExamhall 4.3 Medium2023-03-20
CVE-2022-46867 WordPress Universal Star Rating Plugin <= 2.1.0 is vulnerable to Cross Site Request Forgery (CSRF) — Universal Star Rating 4.3 Medium2023-03-17
CVE-2022-46854 WordPress Launchpad – Coming Soon & Maintenance Mode Plugin Plugin <= 1.0.13 is vulnerable to Cross Site Request Forgery (CSRF) — Launchpad – Coming Soon & Maintenance Mode Plugin 5.4 Medium2023-03-17
CVE-2023-1472 RapidLoad Power-Up for Autoptimize <= 1.7.1 - Cross-Site Request Forgery — RapidLoad AI – Optimize Web Vitals Automatically 6.3 Medium2023-03-17
CVE-2022-38063 WordPress Social Login WP Plugin <= 5.0.0.0 is vulnerable to Cross Site Request Forgery (CSRF) — Social Login WP 5.4 Medium2023-03-16
CVE-2022-47427 WordPress My Calendar Plugin <= 3.3.24.1 is vulnerable to Cross Site Request Forgery (CSRF) — My Calendar 5.4 Medium2023-03-15
CVE-2023-25708 WordPress WP VR – 360 Panorama and Virtual Tour Builder For WordPress Plugin <= 8.2.7 is vulnerable to Cross Site Request Forgery (CSRF) — WP VR – 360 Panorama and Virtual Tour Builder For WordPress 4.3 Medium2023-03-15
CVE-2023-25709 WordPress Locatoraid Store Locator Plugin <= 3.9.11 is vulnerable to Cross Site Request Forgery (CSRF) — Locatoraid Store Locator 5.4 Medium2023-03-15
CVE-2023-25968 WordPress Client Portal – Private user pages and login Plugin <= 1.1.8 is vulnerable to Cross Site Request Forgery (CSRF) — Client Portal – Private user pages and login 4.3 Medium2023-03-15
CVE-2023-24920 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.1 5.4 Medium2023-03-14
CVE-2022-47143 WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.9 is vulnerable to Cross Site Request Forgery (CSRF) — Multiple Page Generator Plugin – MPG 4.3 Medium2023-03-14
CVE-2022-47141 WordPress WP Dynamic Keywords Injector Plugin <= 2.3.15 is vulnerable to Cross Site Request Forgery (CSRF) — WP Dynamic Keywords Injector 5.4 Medium2023-03-14
CVE-2022-47422 WordPress WordPress Stripe Donation and Payment Plugin Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF) — Accept Stripe Donation – AidWP 4.3 Medium2023-03-14
CVE-2022-47147 WordPress ipBlockList Plugin <= 1.0 is vulnerable to Cross Site Request Forgery (CSRF) — ipBlockList 5.4 Medium2023-03-14

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4753 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.