Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4750

4750 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2016-20034 Wowza Streaming Engine 4.5.0 Privilege Escalation via user edit — Wowza Streaming Engine 8.8 High2026-03-15
CVE-2015-20117 RealtyScript 4.0.2 Cross-Site Request Forgery Unauthorized User Creation — RealtyScript 5.3 Medium2026-03-15
CVE-2015-20113 RealtyScript 4.0.2 Multiple Cross-Site Request Forgery and Persistent Cross-Site Scripting Vulnerabilities — RealtyScript 5.3 Medium2026-03-15
CVE-2016-20028 ZKTeco ZKBioSecurity 3.0 Cross-Site Request Forgery Superadmin — ZKTeco ZKBioSecurity 4.3 Medium2026-03-15
CVE-2026-32456 WordPress Admin Menu Editor plugin <= 1.14.1 - Cross Site Request Forgery (CSRF) vulnerability — Admin Menu Editor 8.8 -2026-03-13
CVE-2026-32443 WordPress Product Feed PRO for WooCommerce plugin <= 13.5.2 - Cross Site Request Forgery (CSRF) vulnerability — Product Feed PRO for WooCommerce 8.8 -2026-03-13
CVE-2026-32420 WordPress GamiPress plugin <= 7.6.6 - Cross Site Request Forgery (CSRF) vulnerability — GamiPress 8.8 -2026-03-13
CVE-2026-32344 WordPress Corpiva theme <= 1.0.96 - Cross Site Request Forgery (CSRF) vulnerability — Corpiva 8.8 -2026-03-13
CVE-2026-32343 WordPress Easy Table of Contents plugin <= 2.0.80 - Cross Site Request Forgery (CSRF) vulnerability — Easy Table of Contents 8.3 -2026-03-13
CVE-2026-32342 WordPress Quiz Maker plugin <= 6.7.1.2 - Cross Site Request Forgery (CSRF) vulnerability — Quiz Maker 8.8 -2026-03-13
CVE-2026-32328 WordPress Lemmony theme < 1.7.1 - Cross Site Request Forgery (CSRF) vulnerability — Lemmony 8.8 -2026-03-13
CVE-2026-32330 WordPress Photo Gallery by 10Web plugin <= 1.8.37 - Cross Site Request Forgery (CSRF) vulnerability — Photo Gallery by 10Web 8.8 -2026-03-13
CVE-2026-22215 wpDiscuz before 7.6.47 - Missing CSRF Protection on wpdGetFollowsPage — wpDiscuz 4.3 Medium2026-03-13
CVE-2026-22202 wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email — wpDiscuz 8.1 High2026-03-13
CVE-2026-31954 Emlog asynchronous media file deletion missing CSRF protection — emlog--2026-03-11
CVE-2026-30868 Cross-Site Request Forgery (CSRF) in opnsense/core — core 6.3 Medium2026-03-11
CVE-2026-3903 Modular Connector <= 2.5.1 - Cross-Site Request Forgery via postConfirmOauth — Modular DS: Monitor, update, and backup multiple websites 4.3 Medium2026-03-11
CVE-2026-2324 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.7 - Cross-Site Request Forgery in Booking Form Settings Update to Stored Cross-Site Scripting — LatePoint – Calendar Booking Plugin for Appointments and Events 6.1 Medium2026-03-11
CVE-2026-29113 Craft has a potential information disclosure vulnerability in preview tokens — cms 6.5AIMediumAI2026-03-10
CVE-2026-28495 GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.php — GetSimpleCMS-CE 9.7 Critical2026-03-10
CVE-2026-28281 InstantCMS has Multiple CSRF Vulnerabilities — icms2 7.1 High2026-03-09
CVE-2026-3770 SourceCodester Computer Laboratory Management System cross-site request forgery — Computer Laboratory Management System 4.3 Medium2026-03-08
CVE-2026-29784 Ghost: Incomplete CSRF protections around OTC use — Ghost 7.5 High2026-03-07
CVE-2026-1087 The Guardian News Feed <= 1.2 - Cross-Site Request Forgery to Settings Update — The Guardian News Feed 4.3 Medium2026-03-07
CVE-2026-1086 Font Pairing Preview For Landing Pages <= 1.3 - Cross-Site Request Forgery to Settings Update — Font Pairing Preview For Landing Pages 4.3 Medium2026-03-07
CVE-2026-1085 True Ranker <= 2.2.9 - Cross-Site Request Forgery to Unauthorized True Ranker Disconnection — True Ranker 4.3 Medium2026-03-07
CVE-2026-1073 Purchase Button For Affiliate Link <= 1.0.2 - Cross-Site Request Forgery to Settings Update — Purchase Button For Affiliate Link 4.3 Medium2026-03-07
CVE-2026-2494 ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial — ProfileGrid – User Profiles, Groups and Communities 4.3 Medium2026-03-07
CVE-2026-1644 WP Frontend Profile <= 1.3.8 - Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection — WP Frontend Profile 4.3 Medium2026-03-06
CVE-2018-25200 OOP CMS BLOG 1.0 Cross-Site Request Forgery via addUser.php — OOP CMS BLOG 5.3 Medium2026-03-06

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4750 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.