Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4753

4753 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-11419 Password for WP <= 1.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Password for WP 6.1 Medium2024-12-12
CVE-2024-11689 HQ Rental Software <= 1.5.29 - Cross-Site Request Forgery to Arbitrary Options Update — HQ Rental Software 8.8 High2024-12-12
CVE-2024-28141 Cross-Site Request-Forgery — Scan2Net 8.8 -2024-12-11
CVE-2024-12004 WPC Order Notes for WooCommerce <= 1.5.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting — WPC Order Notes for WooCommerce 6.1 Medium2024-12-11
CVE-2020-28398 Siemens RUGGEDCOM 安全漏洞 — RUGGEDCOM ROX MX5000 8.8 High2024-12-10
CVE-2024-54226 WordPress Country Blocker plugin <= 3.2 - CSRF to Stored XSS vulnerability — Country Blocker 7.1 High2024-12-09
CVE-2023-23726 WordPress Tickera – WordPress Event Ticketing plugin <= 3.5.1.0 - CSRF Leading To Post Status Change Vulnerability — Tickera 5.4 Medium2024-12-09
CVE-2023-28688 WordPress TH Variation Swatches plugin <= 1.2.7 - Cross-Site Request Forgery (CSRF) vulnerability — TH Variation Swatches 5.4 Medium2024-12-09
CVE-2024-12349 JFinalCMS save cross-site request forgery — JFinalCMS 4.3 Medium2024-12-09
CVE-2024-12115 Poll Maker <= 5.5.4 - Cross-Site Request Forgery to Poll Duplication — Poll Maker – Versus Polls, Anonymous Polls, Image Polls 4.3 Medium2024-12-07
CVE-2024-54205 WordPress Paloma Widget plugin <= 1.14 - CSRF to Stored XSS vulnerability — Paloma Widget 7.1 High2024-12-06
CVE-2024-53809 WordPress Namaste! LMS plugin <= 2.6.4.1 - Cross Site Request Forgery (CSRF) vulnerability — Namaste! LMS 4.3 Medium2024-12-06
CVE-2024-11336 Clickbank WordPress Plugin (Storefront) <= 1.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Clickbank WordPress Plugin (Storefront) 6.1 Medium2024-12-06
CVE-2024-11444 CLUEVO LMS, E-Learning Platform <= 1.13.2 - Cross-Site Request Forgery to Module Deletion — CLUEVO LMS, E-Learning Platform 4.3 Medium2024-12-06
CVE-2024-12003 WP System <= 1.1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting — WP System 6.1 Medium2024-12-06
CVE-2024-48846 Cross Side Request Forgery, CSRF — ASPECT-Enterprise 7.1 High2024-12-05
CVE-2024-11341 Simple Redirection <= 1.5 - Cross-Site Request Forgery to Arbitrary Site Redirect — Simple Redirection 4.3 Medium2024-12-05
CVE-2024-11813 Pulsating Chat Button <= 1.4.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Pulsating Chat Button 6.1 Medium2024-12-04
CVE-2024-41776 IBM Cognos Controller cross-site request forgery — Cognos Controller 6.5 Medium2024-12-03
CVE-2024-52477 WordPress Document & Data Automation plugin <= 1.6.1 - CSRF to Stored XSS vulnerability — Document & Data Automation 7.1 High2024-12-02
CVE-2024-52479 WordPress Jobify plugin < 4.3.0 - Cross Site Request Forgery (CSRF) vulnerability — Jobify 4.3 Medium2024-12-02
CVE-2024-53707 WordPress Ahmeti Wp Güzel Sözler plugin <= 4.0 - Cross Site Request Forgery (CSRF) vulnerability — Ahmeti Wp Güzel Sözler 4.3 Medium2024-12-02
CVE-2024-53711 WordPress Hotlink2Watermark plugin <= 0.3.2 - CSRF to Stored XSS vulnerability — Hotlink2Watermark 7.1 High2024-12-02
CVE-2024-53710 WordPress ITERAS plugin <= 1.8.0 - CSRF to Stored XSS vulnerability — ITERAS 7.1 High2024-12-02
CVE-2024-53712 WordPress Kevin's plugin <= 2.0.0 - CSRF to Stored XSS vulnerability — Kevin's 7.1 High2024-12-02
CVE-2024-53713 WordPress Silverlight Video Player plugin <= 1.0 - CSRF to Stored XSS vulnerability — Silverlight Video Player 7.1 High2024-12-02
CVE-2024-53715 WordPress Simple Travel Map plugin <= 0.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerability — Simple Travel Map 7.1 High2024-12-02
CVE-2024-53714 WordPress Continue Shopping From Cart plugin <= 1.3 - CSRF to Stored XSS vulnerability — Continue Shopping From Cart 7.1 High2024-12-02
CVE-2024-53716 WordPress wp auto top plugin <= 2.9.3 - CSRF to Stored Cross Site Scripting (XSS) vulnerability — wp auto top 7.1 High2024-12-02
CVE-2024-53717 WordPress yPHPlista plugin <= 1.1.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerability — yPHPlista 7.1 High2024-12-02

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4753 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.