Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4751

4751 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14168 WP DB Booster <= 1.0.1 - Cross-Site Request Forgery to Database Cleanup — WP DB Booster 4.3 Medium2025-12-20
CVE-2025-14734 Amazon affiliate lite Plugin <= 1.0.0 - Cross-Site Request Forgery to Plugin Settings Update — Amazon affiliate lite Plugin 5.4 Medium2025-12-20
CVE-2025-14164 Quran Gateway <= 1.5 - Cross-Site Request Forgery to Settings Update — Quran Gateway 4.3 Medium2025-12-20
CVE-2025-1927 CSRF in Restajet's Online Food Delivery System — Online Food Delivery System 7.1 High2025-12-19
CVE-2025-59949 FreshRSS has Logout CSRF that Leads to DoS via <track src> — FreshRSS 5.3 Medium2025-12-18
CVE-2025-68434 opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation — opensourcepos 8.8 High2025-12-17
CVE-2025-14266 CSRF in Ercom Cryptobox administration console — Cryptobox 8.8AIHighAI2025-12-17
CVE-2025-62190 CSRF Allows Call Initiation and Message Delivery — Mattermost 4.3 Medium2025-12-17
CVE-2025-14399 Download Plugins and Themes from Dashboard <= 1.9.6 - Cross-Site Request Forgery to Bulk Plugin/Theme Archival — Download Plugins and Themes in ZIP from Dashboard 4.3 Medium2025-12-17
CVE-2025-64700 Weseek Growi 跨站请求伪造漏洞 — GROWI 8.8AIHighAI2025-12-17
CVE-2025-68082 WordPress Semrush Content Toolkit plugin <= 1.1.32 - Cross Site Request Forgery (CSRF) vulnerability — Semrush Content Toolkit 5.4 Medium2025-12-16
CVE-2025-68083 WordPress Meks Quick Plugin Disabler plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerability — Meks Quick Plugin Disabler 5.4 Medium2025-12-16
CVE-2025-64240 WordPress Freshchat plugin <= 2.3.4 - Cross Site Request Forgery (CSRF) vulnerability — Freshchat 8.8AIHighAI2025-12-16
CVE-2025-64239 WordPress RTL Tester plugin <= 1.2 - Cross Site Request Forgery (CSRF) vulnerability — RTL Tester 4.3 Medium2025-12-16
CVE-2025-59009 WordPress Listify theme <= 3.2.5 - Cross Site Request Forgery (CSRF) vulnerability — Listify 8.8AIHighAI2025-12-16
CVE-2025-58999 WordPress WP Attractive Donations System - Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) vulnerability — WP Attractive Donations System - Easy Stripe & Paypal donations 8.8AIHighAI2025-12-16
CVE-2025-64237 WordPress Quick Interest Slider plugin <= 3.1.5 - Cross Site Request Forgery (CSRF) vulnerability — Quick Interest Slider 4.3 Medium2025-12-16
CVE-2025-66407 Weblate has Server-Side Request Forgery vulnerability — weblate 5.0 Medium2025-12-15
CVE-2025-14394 Popover Windows <= 1.2 - Cross-Site Request Forgery to Arbitrary Popover Configuration Update — Popover Windows 4.3 Medium2025-12-13
CVE-2025-14462 Lucky Draw Contests <= 4.2 - Cross-Site Request Forgery to Plugin Settings Update — Lucky Draw Contests 4.3 Medium2025-12-13
CVE-2025-14454 Image Slider by Ays- Responsive Slider and Carousel <= 2.7.0 - Cross-Site Request Forgery to Arbitrary Slider Deletion — Image Slider by Ays- Responsive Slider and Carousel 4.3 Medium2025-12-13
CVE-2025-13970 OpenPLC_V3 Cross-Site Request Forgery — OpenPLC_V3 8.0 High2025-12-13
CVE-2025-12407 Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion — Events Manager – Calendar, Bookings, Tickets, and more! 4.3 Medium2025-12-12
CVE-2025-14159 Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Export — Secure Copy Content Protection and Content Locking 4.3 Medium2025-12-12
CVE-2025-58576 Japan Total System多款产品 跨站请求伪造漏洞 — GroupSession Free edition 8.8AIHighAI2025-12-12
CVE-2025-14391 Simple Theme Changer <= 1.0 - Cross-Site Request Forgery to Arbitrary Theme Switcher Configuration Update — Simple Theme Changer 4.3 Medium2025-12-12
CVE-2025-13366 Rabbit Hole <= 1.1 - Cross-Site Request Forgery to Settings Reset — Rabbit Hole 4.3 Medium2025-12-12
CVE-2025-14160 Upcoming for Calendly <= 1.2.4 - Cross-Site Request Forgery to Settings Update — Upcoming for Calendly 4.3 Medium2025-12-12
CVE-2025-13987 Purchase and Expense Manager <= 1.1.2 - Cross-Site Request Forgery to Arbitrary Purchase Record Deletion — Purchase and Expense Manager 4.3 Medium2025-12-12
CVE-2025-14062 Animated Pixel Marquee Creator <= 1.0.0 - Cross-Site Request Forgery via 'marquee' Parameter — Animated Pixel Marquee Creator 4.3 Medium2025-12-12

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4751 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.