Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4753

4753 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-54430 WordPress EELV Newsletter plugin <= 4.8.2 - Cross Site Request Forgery (CSRF) vulnerability — EELV Newsletter 5.4 Medium2024-12-16
CVE-2024-54429 WordPress Aphorismus plugin <= 1.2.0 - CSRF to Stored XSS vulnerability — Aphorismus 7.1 High2024-12-16
CVE-2024-54431 WordPress Admin Customization plugin <= 2.2 - CSRF to Stored XSS vulnerability — Admin Customization 7.1 High2024-12-16
CVE-2024-54433 WordPress Simple Booking – Widget plugin <= 1.1 - CSRF to Stored XSS vulnerability — Simple Booking Widget 7.1 High2024-12-16
CVE-2024-54432 WordPress WP Flipkart Importer plugin <= 1.4 - CSRF to Stored XSS vulnerability — WP Flipkart Importer 7.1 High2024-12-16
CVE-2024-54434 WordPress phZoom plugin <= 1.2.92 - CSRF to Stored XSS vulnerability — phZoom 7.1 High2024-12-16
CVE-2024-54435 WordPress Onlywire Multi Autosubmitter plugin <= 1.2.4 - CSRF to Stored XSS vulnerability — Onlywire Multi Autosubmitter 7.1 High2024-12-16
CVE-2024-54436 WordPress Jet Footer Code plugin <= 1.4 - CSRF to Stored XSS vulnerability — Jet Footer Code 7.1 High2024-12-16
CVE-2024-54438 WordPress Gaxx Keywords plugin <= 0.2 - CSRF to Stored XSS vulnerability — Gaxx Keywords 7.1 High2024-12-16
CVE-2024-54439 WordPress Amazon Product Price plugin <= 1.1 - CSRF to Stored XSS vulnerability — Amazon Product Price 7.1 High2024-12-16
CVE-2024-54440 WordPress WP-Ban-User plugin <= 1.0 - CSRF to Stored XSS vulnerability — WP-Ban-User 7.1 High2024-12-16
CVE-2024-56012 WordPress Flash News / Post (Responsive) plugin <= 4.1 - CSRF to Privilege Escalation vulnerability — Flash News / Post (Responsive) 9.8 Critical2024-12-16
CVE-2024-12646 Chunghwa Telecom topm-client - Arbitrary File Delete — topm-client 8.1 High2024-12-16
CVE-2024-12645 Chunghwa Telecom topm-client - Arbitrary File Read — topm-client 6.5 Medium2024-12-16
CVE-2024-12644 Chunghwa Telecom tbm-client - Arbitrary File Copy and Paste — tbm-client 7.1 High2024-12-16
CVE-2024-12643 Chunghwa Telecom tbm-client - Arbitrary File Delete — tbm-client 8.1 High2024-12-16
CVE-2024-12642 Chunghwa Telecom TenderDocTransfer - Arbitrary File Write — TenderDocTransfer 8.1 High2024-12-16
CVE-2024-12555 SIP Calculator <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — SIP Calculator 6.1 Medium2024-12-14
CVE-2024-54351 WordPress Fancy Roller Scroller plugin <= 1.4.0 - CSRF to Stored XSS vulnerability — Fancy Roller Scroller 7.1 High2024-12-13
CVE-2024-54337 WordPress DX Dark Site plugin <= 1.0.1 - CSRF to Stored Cross-Site Scripting vulnerability — DX Dark Site 7.1 High2024-12-13
CVE-2024-54321 WordPress Hive Support plugin <= 1.1.2 - Cross Site Request Forgery (CSRF) vulnerability — Hive Support 4.3 Medium2024-12-13
CVE-2024-54307 WordPress AIcomments plugin <= 1.4.1 - Cross Site Request Forgery (CSRF) vulnerability — AIcomments 4.3 Medium2024-12-13
CVE-2024-54306 WordPress AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) vulnerability — AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot 4.3 Medium2024-12-13
CVE-2024-54300 WordPress AutoWP plugin <= 2.0.8 - Cross Site Request Forgery (CSRF) vulnerability — AutoWP 4.3 Medium2024-12-13
CVE-2024-54248 WordPress Eewee Admin Custom plugin <= 1.8.2.4 - CSRF to Privilege Escalation vulnerability — eewee admin custom 8.8 High2024-12-13
CVE-2023-41686 WordPress Woocommerce Support System plugin <= 1.2.2 - Cross Site Request Forgery (CSRF) vulnerability — Woocommerce Support System 6.5 Medium2024-12-13
CVE-2024-12414 Themify Store Locator <= 1.1.9 - Cross-Site Request Forgery — Themify Store Locator 4.3 Medium2024-12-13
CVE-2024-12572 Hello in All Languages <= 1.0.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Hello In All Languages 6.1 Medium2024-12-13
CVE-2024-12526 Arena.IM – Live Blogging for real-time events <= 0.4.1 - Cross-Site Request Forgery to Settings Update — Arena.IM – Live Blogging for real-time events 4.3 Medium2024-12-12
CVE-2024-11417 dejure.org Vernetzungsfunktion <= 1.97.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — dejure.org Vernetzungsfunktion 6.1 Medium2024-12-12

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4753 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.