Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4753

4753 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-10040 Infinite-Scroll <= 2.6.2 - Cross-Site Request Forgery to Plugin Settings Update — Infinite-Scroll 5.3 Medium2024-10-18
CVE-2024-49220 WordPress Cookie Scanner plugin <= 1.1 - CSRF to Stored XSS vulnerability — Cookie Scanner 6.1AIMediumAI2024-10-17
CVE-2024-49221 WordPress cSlider plugin <= 2.4.2 - CSRF to Stored XSS vulnerability — cSlider 6.1AIMediumAI2024-10-17
CVE-2024-49223 WordPress CJ Change Howdy plugin <= 3.3.1 - CSRF to Stored XSS vulnerability — CJ Change Howdy 6.1AIMediumAI2024-10-17
CVE-2024-49237 WordPress Ahmeti Wp Timeline plugin <= 5.1 - CSRF to Stored XSS vulnerability — Ahmeti Wp Timeline 7.1 High2024-10-17
CVE-2024-49304 WordPress Pinpoint Booking System plugin <= 2.9.9.5.7 - CSRF to Stored Cross Site Scripting (XSS) vulnerability — Pinpoint Booking System 5.4 Medium2024-10-17
CVE-2024-49313 WordPress VKontakte Wall Post plugin <= 2.0 - Cross Site Scripting (XSS) vulnerability — VKontakte Wall Post 7.1 High2024-10-17
CVE-2024-48048 WordPress Wsify Widget plugin <= 1.0 - CSRF to Stored XSS vulnerability — Wsify Widget 7.1 High2024-10-17
CVE-2024-48031 WordPress Featured Posts with Multiple Custom Groups (FPMCG) plugin <= 4.0 - Cross-Site Request Forgery (CSRF) vulnerability — Featured Posts with Multiple Custom Groups (FPMCG) 6.5 Medium2024-10-17
CVE-2024-48037 WordPress Contact Form Widget plugin <= 1.4.2 - CSRF vulnerability — Contact Form Widget 5.4 Medium2024-10-17
CVE-2024-48038 WordPress wp-Monalisa plugin <= 6.4 - Cross Site Request Forgery (CSRF) vulnerability — wp-Monalisa 4.3 Medium2024-10-17
CVE-2024-48047 WordPress Linked Variation for WooCommerce plugin <= 1.0.5 - Cross Site Request Forgery (CSRF) vulnerability — Linked Variation for WooCommerce 4.3 Medium2024-10-17
CVE-2024-9352 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder 4.3 Medium2024-10-17
CVE-2024-9351 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder 4.3 Medium2024-10-17
CVE-2024-20421 Cisco ATA 190 Series Analog Telephone Adapter Firmware Cross-Site Request Forgery Vulnerability — Cisco Analog Telephone Adaptor (ATA) Software 7.1 High2024-10-16
CVE-2024-45693 Apache CloudStack: Request origin validation bypass makes account takeover possible — Apache CloudStack 8.0 High2024-10-16
CVE-2024-8507 File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload — File Manager Pro 8.8 High2024-10-16
CVE-2020-36839 WP Lead Plus X <= 0.99 - Cross-Site Request Forgery — WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X 8.3 High2024-10-16
CVE-2020-36836 WP Fastest Cache <= 0.9.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion — WP Fastest Cache – WordPress Cache Plugin 8.0 High2024-10-16
CVE-2024-9649 WP ULike <= 4.7.4 - Cross-Site Request Forgery to Statistic Deletion — WP ULike – Like & Dislike Buttons for Engagement and Feedback 4.3 Medium2024-10-16
CVE-2024-49340 IBM Watson Studio Local cross-site request forgery — Watson Studio Local 4.3 Medium2024-10-15
CVE-2024-48913 Hono vulnerable to bypass of CSRF Middleware by a request without Content-Type header. — hono 5.9 Medium2024-10-15
CVE-2024-45737 Maintenance mode state change of App Key Value Store (KVStore) through Cross-Site Request Forgery (CSRF) — Splunk Enterprise 4.3 Medium2024-10-14
CVE-2024-46911 Apache Roller: Weakness in CSRF protection allows privilege escalation — Apache Roller 8.8AIHighAI2024-10-14
CVE-2024-6959 Denial of Service (DOS) in multipart boundary while uploading file in parisneo/lollms-webui — parisneo/lollms-webui 7.5 -2024-10-13
CVE-2024-9778 ImagePress – Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update — ImagePress – Image Gallery 4.3 Medium2024-10-12
CVE-2024-9592 Easy PayPal Gift Certificate <= 1.2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_options — Easy PayPal Gift Certificate 6.1 Medium2024-10-12
CVE-2024-8477 Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.87 - Cross-Site Request Forgery — Brevo – Email, SMS, Web Push, Chat, and more. 4.3 Medium2024-10-10
CVE-2024-47828 Cross-Site Request Forgery in ampache — ampache 5.3 Medium2024-10-09
CVE-2024-44028 WordPress NiceJob plugin < 3.6.5 - CSRF to Stored Cross Site Scripting (XSS) vulnerability — NiceJob 7.1 High2024-10-06

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4753 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.