Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4753

4753 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-39681 WordPress Cooked Plugin - Cross-Site Request Forgery to Apply Template to All Recipes — Cooked 5.4 Medium2024-07-17
CVE-2024-39680 WordPress Cooked Plugin - Cross-Site Request Forgery to Default Recipe Template Save — Cooked 5.4 Medium2024-07-17
CVE-2024-39679 WordPress Cooked Plugin - Cross-Site Request Forgery to Recipe Template Reset — Cooked 4.3 Medium2024-07-17
CVE-2024-39678 WordPress Cooked Plugin - Cross-Site Request Forgery to Get Recipe IDs — Cooked 4.3 Medium2024-07-17
CVE-2024-5815 Cross Site Request Forgery was identified in GitHub Enterprise Server that allowed write in a user owned repository — GitHub Enterprise Server 5.7AIMediumAI2024-07-16
CVE-2024-37938 WordPress SociallyViral theme <= 1.0.10 - Cross Site Request Forgery (CSRF) vulnerability — SociallyViral 4.3 Medium2024-07-12
CVE-2024-37939 WordPress Patricia Lite theme <= 1.2.3 - Cross Site Request Forgery (CSRF) vulnerability — Patricia Lite 4.3 Medium2024-07-12
CVE-2024-37940 WordPress Seraphinite Accelerator (Full, premium) plugin <= 2.21.13 - CSRF Leading to Arbitrary File Deletion vulnerability — Seraphinite Accelerator (Full, premium) 7.4 High2024-07-12
CVE-2024-37941 WordPress Internal Link Juicer: SEO Auto Linker for WordPress plugin <= 2.24.3 - Cross Site Request Forgery (CSRF) vulnerability — Internal Link Juicer: SEO Auto Linker for WordPress 4.3 Medium2024-07-12
CVE-2024-35773 WordPress Comment Reply Email plugin <= 1.3 - CSRF to Stored XSS vulnerability — Comment Reply Email 7.1 High2024-07-12
CVE-2024-37213 WordPress AliExpress Dropshipping with AliNext Lite plugin <= 3.4.6 - CSRF to XSS vulnerability — AliNext 7.1 High2024-07-12
CVE-2024-1375 Event post <= 5.9.10 - Cross-Site Request Forgery — Event post 4.3 Medium2024-07-12
CVE-2024-6649 SourceCodester Employee and Visitor Gate Pass Logging System Users.php save_users cross-site request forgery — Employee and Visitor Gate Pass Logging System 4.3 Medium2024-07-10
CVE-2024-28828 1-Click compromize via CSRF — Checkmk 8.8 High2024-07-10
CVE-2024-3798 Insecure handling of GET argument in Phoniebox — Phoniebox 8.8AIHighAI2024-07-10
CVE-2024-27783 Fortinet FortiAIOps 跨站请求伪造漏洞 — FortiAIOps 7.2 High2024-07-09
CVE-2024-6168 Just Custom Fields <= 3.3.2 - Cross-Site Request Forgery via AJAX actions — Just Custom Fields 4.3 Medium2024-07-09
CVE-2024-4100 Pricing Table <= 2.0.1 - Cross-Site Request Forgery via ajax() — Pricing Table 5.3 Medium2024-07-09
CVE-2024-6320 ScrollTo Top <= 1.2.2 - Cross-Site Request Forgery to Arbitrary File Upload — ScrollTo Top 8.8 High2024-07-09
CVE-2024-6321 ScrollTo Bottom <= 1.1.1 - Cross-Site Request Forgery to Arbitrary File Upload — ScrollTo Bottom 8.8 High2024-07-09
CVE-2024-6310 Advanced AJAX Page Loader <= 2.7.7 - Cross-Site Request Forgery to Arbitrary File Upload — Advanced AJAX Page Loader 8.8 High2024-07-09
CVE-2024-6309 Attachment File Icons (AF Icons) <= 1.3 - Cross-Site Request Forgery to Arbitrary File Upload — Attachment File Icons (AF Icons) 8.8 High2024-07-09
CVE-2024-6316 Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Upload — Generate PDF using Contact Form 7 8.8 High2024-07-09
CVE-2024-6317 Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Deletion — Generate PDF using Contact Form 7 8.8 High2024-07-09
CVE-2024-37923 WordPress Cliengo – Chatbot plugin <= 3.0.4 - Cross Site Request Forgery (CSRF) vulnerability — Cliengo – Chatbot 5.4 Medium2024-07-09
CVE-2023-47677 Realtek AP-Router SDK 跨站请求伪造漏洞 — WBR-6013 8.8 High2024-07-08
CVE-2024-5616 CSRF Vulnerability in mudler/LocalAI — mudler/localai 4.3AIMediumAI2024-07-06
CVE-2024-5943 Nested Pages <= 3.2.7 - Cross-Site Request Forgery to Local File Inclusion — Nested Pages 8.8 High2024-07-04
CVE-2024-4543 Snippet Shortcodes <= 4.1.4 - Cross-Site Request Forgery — Snippet Shortcodes 4.3 Medium2024-07-03
CVE-2024-39326 SkillTree CSRF Vulnerability allows an attacker to modify the Video and Captions of a Skill — skills-service 4.4 Medium2024-07-02

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4753 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.