Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4751

4751 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13753 Ultimate Classified Listings <= 1.5 - Cross-Site Request Forgery to Account Takeover — Ultimate Classified Listings 8.1 High2025-02-20
CVE-2024-13339 DeBounce Email Validator <= 5.8.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — DeBounce Email Validator 6.1 Medium2025-02-19
CVE-2024-13336 Disable Auto Updates <= 1.4 - Cross-Site Request Forgery to Auto-update Disable — Disable Auto Updates 4.3 Medium2025-02-19
CVE-2024-13405 Apptivo Business Site CRM <= 5.3 - Cross-Site Request Forgery to IP Address Block — Apptivo Business Site 4.3 Medium2025-02-19
CVE-2025-0865 WP Media Category Management 2.0 - 2.3.3 - Cross-Site Request Forgery to Settings Update — WP Media Category Management 6.5 Medium2025-02-19
CVE-2025-1441 Royal Elementor Addons and Templates <= 1.7.1007 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — Royal Addons for Elementor – Addons and Templates Kit for Elementor 6.1 Medium2025-02-19
CVE-2024-13718 Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification — Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later 4.3 Medium2025-02-18
CVE-2024-13795 Ecwid by Lightspeed Ecommerce Shopping Cart <= 6.12.27 - Cross-Site Request Forgery to Send Deactivation Message — Ecwid by Lightspeed Ecommerce Shopping Cart 4.3 Medium2025-02-18
CVE-2024-13523 MemorialDay <= 1.0.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting — MemorialDay 6.1 Medium2025-02-18
CVE-2024-13315 Shopwarden – Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update — Shopwarden – Automated WooCommerce monitoring & testing 8.8 High2025-02-18
CVE-2024-13438 SpeedSize Image & Video AI-Optimizer <= 1.5.1 - Cross-Site Request Forgery to Clear Cache — SpeedSize Image & Video AI-Optimizer 4.3 Medium2025-02-18
CVE-2024-13555 1 Click WordPress Migration Plugin – 100% FREE for a limited time <= 2.2 - Cross-Site Request Forgery to Backup Process Cancellation — 1 Click Migration & Backup: Free WordPress Migration Plugin with Zero Downtime & Easy Clone 5.3 Medium2025-02-18
CVE-2024-13852 Option Editor <= 1.0 - Cross-Site Request Forgery to Arbitrary Options Update — Option Editor 8.8 High2025-02-18
CVE-2025-0796 Mortgage Lead Capture System <= 8.2.11 - Cross-Site Request Forgery to Settings Reset — WPrequal 4.3 Medium2025-02-18
CVE-2024-13684 Reset <= 1.6 - Cross-Site Request Forgery to Database Reset — Reset 8.1 High2025-02-18
CVE-2024-13522 magayo Lottery Results <= 2.0.12 - Cross-Site Request Forgery to Stored Cross-Site Scripting — magayo Lottery Results 6.1 Medium2025-02-18
CVE-2025-26768 WordPress what3words Address Field plugin <= 4.0.15 - CSRF to Stored XSS vulnerability — what3words Address Field 7.1 High2025-02-16
CVE-2025-26759 WordPress Content Snippet Manager plugin <= 1.1.5 - CSRF to Stored XSS vulnerability — Content Snippet Manager 7.1 High2025-02-16
CVE-2025-1358 Pix Software Vivaz cross-site request forgery — Vivaz 4.3 Medium2025-02-16
CVE-2024-10581 DirectoryPress Frontend <= 2.7.9 - Cross-Site Request Forgery to Listing Status Update — DirectoryPress Frontend 4.3 Medium2025-02-15
CVE-2025-22705 WordPress Disqus Popular Posts plugin <= 2.1.1 - CSRF to Reflected Cross Site Scripting (XSS) vulnerability — Disqus Popular Posts 7.1 High2025-02-14
CVE-2025-24699 WordPress WP Coder Plugin <= 3.6 - CSRF to Cross Site Scripting (XSS) vulnerability — WP Coder 7.1 High2025-02-14
CVE-2025-23411 mySCADA myPRO Manager Cross-Site Request Forgery — myPRO Manager 6.3 Medium2025-02-13
CVE-2025-26582 WordPress TinyMCE Advanced qTranslate fix editor problems plugin <= 1.0.0 - CSRF to Stored XSS vulnerability — TinyMCE Advanced qTranslate fix editor problems 7.1 High2025-02-13
CVE-2025-26580 WordPress Page/Post Specific Social Share Buttons plugin <= 2.1 - CSRF to Stored XSS vulnerability — Page/Post Specific Social Share Buttons 7.1 High2025-02-13
CVE-2025-26578 WordPress Simple Documentation plugin <= 1.2.8 - CSRF to Stored XSS vulnerability — Simple Documentation 7.1 High2025-02-13
CVE-2025-26577 WordPress DX-auto-publish plugin <= 1.2 - CSRF to Stored XSS vulnerability — DX-auto-publish 7.1 High2025-02-13
CVE-2025-26572 WordPress WP PHPList Plugin <= 1.7 - CSRF to Stored XSS vulnerability — WP PHPList 7.1 High2025-02-13
CVE-2025-26571 WordPress Wibiya Toolbar plugin <= 2.0 - CSRF to Stored XSS vulnerability — Wibiya Toolbar 7.1 High2025-02-13
CVE-2025-26570 WordPress Glance That plugin <= 4.9 - CSRF to Stored XSS vulnerability — Glance That 7.1 High2025-02-13

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4751 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.