Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4751

4751 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-24879 SupportCandy < 2.2.7 - CSRF to Cross-Site Scripting — SupportCandy – Helpdesk & Support Ticket System 7.3 -2022-02-07
CVE-2021-24843 SupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRF — SupportCandy – Helpdesk & Support Ticket System 6.5 -2022-02-07
CVE-2021-25095 IP2Location Country Blocker < 2.26.5 - Subscriber+ Arbitrary Country Ban — IP2Location Country Blocker 5.4 -2022-02-07
CVE-2020-7534 Schneider Electric 多款产品跨站请求伪造漏洞 — Modicon M340 CPUs: BMXP34 (All Versions), Modicon Quantum CPUs with integrated Ethernet (Copro): 140CPU65 (All Versions), Modicon Premium CPUs with integrated Ethernet (Copro): TSXP57 (All Versions), Modicon M340 ethernet modules: (BMXNOC0401, BMXNOE01, BMXNOR0200H) (All Versions), Modicon Quantum and Premium factory cast communication modules: (140NOE77111, 140NOC78*00, TSXETY5103, TSXETY4103) 8.8 -2022-02-04
CVE-2021-32732 Cross-Site Request Forgery in xwiki-platform — xwiki-platform 7.5 High2022-02-04
CVE-2021-25092 Link Library < 7.2.8 - Library Settings Reset via CSRF — Link Library 6.5 -2022-02-01
CVE-2021-25072 NextScripts: Social Networks Auto-Poster < 4.3.25 - Arbitrary Post Deletion via CSRF — NextScripts: Social Networks Auto-Poster 6.5 -2022-02-01
CVE-2021-24761 Error Log Viewer < 1.1.2 - Arbitrary Text File Deletion via CSRF — Error Log Viewer by BestWebSoft 6.5 -2022-02-01
CVE-2022-23601 CSRF token missing in Symfony — symfony 8.1 High2022-02-01
CVE-2021-25097 LabTools <= 1.0 - Subscriber+ Arbitrary Publication Deletion — LabTools 6.5 -2022-02-01
CVE-2022-0335 Moodle 跨站请求伪造漏洞 — moodle 8.8 -2022-01-25
CVE-2022-0269 Cross-Site Request Forgery (CSRF) in yetiforcecompany/yetiforcecrm — yetiforcecompany/yetiforcecrm 8.1 -2022-01-24
CVE-2021-25073 WP125 < 1.5.5 - Arbitrary Ad Deletion via CSRF — WP125 6.5 -2022-01-24
CVE-2021-24989 Accept Donations with PayPal < 1.3.4 - Arbitrary Post Deletion via CSRF — Accept Donations with PayPal 6.5 -2022-01-24
CVE-2021-24936 WP Extra File Types < 0.5.1 - CSRF to Stored Cross-Site Scripting — WP Extra File Types 8.2 -2022-01-24
CVE-2021-24696 Simple Download Monitor < 3.9.9 - Multiple CSRF — Simple Download Monitor 8.8 -2022-01-24
CVE-2021-44777 WordPress Email Tracker plugin <= 5.2.6 - Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion — Email Tracker (WordPress plugin) 5.4 Medium2022-01-19
CVE-2022-0215 XootiX Plugins <= Various Versions Cross-Site Request Forgery to Arbitrary Options Update — Login/Signup Popup 8.8 High2022-01-18
CVE-2021-43353 Crisp Live Chat <= 0.31 Cross-Site Request Forgery to Stored Cross-Site Scripting — Crisp Live Chat 8.8 High2022-01-18
CVE-2022-0245 Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat — livehelperchat/livehelperchat 6.5 -2022-01-18
CVE-2021-4164 Cross-Site Request Forgery (CSRF) in janeczku/calibre-web — janeczku/calibre-web 8.1 -2022-01-17
CVE-2021-25025 Event Calendar < 1.1.51 - Subscriber+ Event Creation — EventCalendar 4.3 -2022-01-17
CVE-2022-0238 Cross-Site Request Forgery (CSRF) in phoronix-test-suite/phoronix-test-suite — phoronix-test-suite/phoronix-test-suite 4.3 -2022-01-16
CVE-2022-0226 Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat — livehelperchat/livehelperchat 4.3 -2022-01-14
CVE-2022-0231 Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat — livehelperchat/livehelperchat 4.3 -2022-01-14
CVE-2021-23227 WordPress PHP Everywhere Plugin <= 2.0.2 is vulnerable to Cross Site Request Forgery (CSRF) — PHP Everywhere (WordPress plugin) 5.4 Medium2022-01-13
CVE-2022-0196 Cross-Site Request Forgery (CSRF) in phoronix-test-suite/phoronix-test-suite — phoronix-test-suite/phoronix-test-suite 4.3 -2022-01-13
CVE-2022-0197 Cross-Site Request Forgery (CSRF) in phoronix-test-suite/phoronix-test-suite — phoronix-test-suite/phoronix-test-suite 4.3 -2022-01-13
CVE-2021-37198 Siemens Comos 跨站请求伪造漏洞 — COMOS V10.2 8.8 -2022-01-11
CVE-2021-25052 Button Generator < 2.3.3 - RFI leading to RCE via CSRF — Button Generator – easily Button Builder 8.8 -2022-01-10

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4751 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.