Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4751

4751 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-66629 HedgeDoc is missing state parameter in OAuth2 flows could lead to CSRF — hedgedoc 3.7 Low2025-12-05
CVE-2025-12879 User Generator and Importer <= 1.2.2 - Cross-Site Request Forgery to Privilege Escalation via Arbitrary Administrator Account Creation — User Generator and Importer 8.8 High2025-12-05
CVE-2025-12130 WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion — WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors 4.3 Medium2025-12-05
CVE-2025-13684 ARK Related Posts <= 2.19 - Cross-Site Request Forgery to Settings Update — ARK Related Posts 4.3 Medium2025-12-05
CVE-2025-12373 Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.9 - Cross-Site Request Forgery To Plugin's Settings Modification — Torod – The smart shipping and delivery portal for e-shops and retailers 4.3 Medium2025-12-05
CVE-2025-12190 Image Optimizer by wps.sk <= 1.2.0 - Cross-Site Request Forgery to Bulk Image Optimization — Image Optimizer by wps.sk 4.3 Medium2025-12-05
CVE-2025-12128 Hide Categories Or Products On Shop Page <= 1.0.7 - Cross-Site Request Forgery to Settings Update — Hide Categories Or Products On Shop Page 4.3 Medium2025-12-05
CVE-2025-12189 Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.11.1374 - Cross-Site Request Forgery to Arbitrary File Upload — Bread & Butter: AI-Powered Lead Intelligence 4.3 Medium2025-12-05
CVE-2025-10055 Time Sheets <= 2.1.3 - Cross-Site Request Forgery — Time Sheets 4.3 Medium2025-12-05
CVE-2025-13360 Quantic Social Image Hover <= 1.0.8 - Cross-Site Request Forgery to Settings Update — Quantic Social Image Hover 4.3 Medium2025-12-05
CVE-2025-13621 dream gallery <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action — dream gallery 6.1 Medium2025-12-05
CVE-2025-13144 ContentStudio <= 1.3.7 - Cross-Site Request Forgery to Settings Update — ContentStudio 4.3 Medium2025-12-05
CVE-2025-13362 Norby AI <= 1.0.3 - Cross-Site Request Forgery to Settings Update — Norby AI 4.3 Medium2025-12-05
CVE-2025-11759 Backup, Restore and Migrate your sites with XCloner <= 4.8.2 - Cross-Site Request Forgery in Xcloner_Remote_Storage:save() — Backup, Restore and Migrate your sites with XCloner 4.3 Medium2025-12-05
CVE-2024-45538 Synology DiskStation Manager和Synology Unified Controller 跨站请求伪造漏洞 — DiskStation Manager (DSM) 9.6 Critical2025-12-04
CVE-2025-12358 ShopEngine <= 4.8.5 - Cross-Site Request Forgery to Wishlist Manipulation — ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution 4.3 Medium2025-12-03
CVE-2025-13871 The feature to manage resources is prone to Cross-Site Request Forgery attacks — Opinio 8.8AIHighAI2025-12-02
CVE-2025-13685 Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actions — Photo Gallery by Ays – Responsive Image Gallery 4.3 Medium2025-12-02
CVE-2025-13140 SurveyJS: Drag & Drop WordPress Form Builder <= 1.12.20 - Cross-Site Request Forgery to Survey Deletion — SurveyJS: Drag & Drop Form Builder 4.3 Medium2025-12-02
CVE-2025-13606 Export All Posts, Products, Orders, Refunds & Users <= 2.19 - Cross-Site Request Forgery to Sensitive Information Exposure — Export All Posts, Products, Orders, Refunds & Users 6.5 Medium2025-12-02
CVE-2024-53684 Socomec DIRIS Digiware M-70 安全漏洞 — DIRIS Digiware M-70 7.5 High2025-12-01
CVE-2025-13296 CSRF in Tekrom Technology's T-Soft E-Commerce — T-Soft E-Commerce 5.4 Medium2025-12-01
CVE-2025-13790 Scada-LTS cross-site request forgery — Scada-LTS 4.3 Medium2025-11-30
CVE-2025-53897 Kiteworks MFT has a Cross-Site Request Forgery (CSRF) vulnerability — security-advisories 6.8 Medium2025-11-29
CVE-2025-13737 Nextend Social Login and Register <= 3.1.21 - Cross-Site Request Forgery to Unlink User Social Login — Nextend Social Login and Register 4.3 Medium2025-11-28
CVE-2025-13143 Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection — Quiz, Poll & Survey Maker by Opinion Stage 4.3 Medium2025-11-27
CVE-2025-12578 Reuters Direct <= 3.0.0 - Cross-Site Request Forgery to Settings Reset — Reuters Direct 4.3 Medium2025-11-27
CVE-2025-12587 Peer Publish <= 1.0 - Cross-Site Request Forgery — Peer Publish 4.3 Medium2025-11-25
CVE-2025-12586 Conditional Maintenance Mode for WordPress <= 1.0.0 - Cross-Site Request Forgery — Conditionnal Maintenance Mode for WordPress 4.3 Medium2025-11-25
CVE-2025-62497 Sony SNC-CX600W 跨站请求伪造漏洞 — SNC-CX600W 8.8AIHighAI2025-11-25

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4751 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.