Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4754

4754 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0590 Microsoft Clarity <= 0.9.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Microsoft Clarity 6.1 Medium2024-02-20
CVE-2024-0512 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_wishlist — Royal Addons for Elementor – Addons and Templates Kit for Elementor 4.3 Medium2024-02-20
CVE-2024-1335 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in disableOptimization — ImageRecycle pdf & image compression 4.3 Medium2024-02-20
CVE-2024-0514 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via add_to_compare — Royal Addons for Elementor – Addons and Templates Kit for Elementor 4.3 Medium2024-02-20
CVE-2024-0515 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_compare — Royal Addons for Elementor – Addons and Templates Kit for Elementor 4.3 Medium2024-02-20
CVE-2024-1338 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in stopOptimizeAll — ImageRecycle pdf & image compression 4.3 Medium2024-02-20
CVE-2024-0513 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via remove_from_wishlist — Royal Addons for Elementor – Addons and Templates Kit for Elementor 4.3 Medium2024-02-20
CVE-2024-0379 Custom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update — Custom Twitter Feeds – A Tweets Widget or X Feed Widget 4.3 Medium2024-02-20
CVE-2024-1339 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Plugin Data Removal in reinitialize — ImageRecycle pdf & image compression 4.3 Medium2024-02-20
CVE-2024-1334 ImageRecycle pdf & image compression <= 3.1.13 - Cross-Site Request Forgery to Settings Update in enableOptimization — ImageRecycle pdf & image compression 4.3 Medium2024-02-20
CVE-2024-25982 Msa-24-0005: csrf risk in language import utility 4.3 Medium2024-02-19
CVE-2024-20718 [Spain] CSRF to delete Requisition Lists at Adobe Commerce — Adobe Commerce 4.3 Medium2024-02-15
CVE-2024-21381 Microsoft Azure Active Directory B2C Spoofing Vulnerability — Entra 6.8 Medium2024-02-13
CVE-2024-25914 WordPress SMTP Mail Plugin <= 1.3.20 is vulnerable to Cross Site Request Forgery (CSRF) — SMTP Mail 4.3 Medium2024-02-13
CVE-2024-24875 WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Request Forgery (CSRF) — Link Library 4.3 Medium2024-02-12
CVE-2024-24884 WordPress Contact Form 7 Connector Plugin <= 1.2.2 is vulnerable to Cross Site Request Forgery (CSRF) — Contact Form 7 Connector 4.3 Medium2024-02-12
CVE-2024-24887 WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF) — Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress 5.4 Medium2024-02-12
CVE-2024-24929 WordPress WP Contact Form Plugin <= 1.6 is vulnerable to Cross Site Request Forgery (CSRF) — WP Contact Form 4.3 Medium2024-02-12
CVE-2024-24935 WordPress Basic Log Viewer Plugin <= 1.0.4 is vulnerable to Cross Site Request Forgery (CSRF) — Basic Log Viewer 4.3 Medium2024-02-12
CVE-2024-23319 CSRF issue allows disconnecting a user's Jira connection through a simple post message (Jira Plugin) — Mattermost 3.5 Low2024-02-09
CVE-2024-24819 icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRF — icingaweb2-module-incubator 5.3 Medium2024-02-09
CVE-2024-24820 Icinga Director configuration is susceptible to Cross-Site Request Forgery — icingaweb2-module-director 8.3 High2024-02-09
CVE-2024-0511 Royal Elementor Addons and Templates <= 1.3.87 - Cross-Site Request Forgery via wpr_update_form_action_meta — Royal Addons for Elementor – Addons and Templates Kit for Elementor 4.3 Medium2024-02-08
CVE-2024-24706 WordPress WP-CFM Plugin <= 1.7.8 is vulnerable to Cross Site Request Forgery (CSRF) — WP-CFM 5.4 Medium2024-02-07
CVE-2024-20255 Cisco Expressway Series 跨站请求伪造漏洞 — Cisco TelePresence Video Communication Server (VCS) Expressway 8.2 High2024-02-07
CVE-2024-20254 Cisco Expressway Series 跨站请求伪造漏洞 — Cisco TelePresence Video Communication Server (VCS) Expressway 9.6 Critical2024-02-07
CVE-2024-20252 Cisco Expressway Series 跨站请求伪造漏洞 — Cisco TelePresence Video Communication Server (VCS) Expressway 9.6 Critical2024-02-07
CVE-2023-38579 Westermo Lynx 206-F2G Cross-Site Request Forgery — Lynx 8.0 High2024-02-06
CVE-2024-24593 Allegro 跨站请求伪造漏洞 — ClearML 9.6 Critical2024-02-06
CVE-2024-0428 Index Now <= 2.6.3 - Cross-Site Request Forgery via reset_form — CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor 7.1 High2024-02-05

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4754 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.