Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-352 (跨站请求伪造(CSRF)) — Vulnerability Class 4756

4756 vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-49621 WordPress APA Register Newsletter Form plugin <= 1.0.0 - CSRF to SQL Injection vulnerability — APA Register Newsletter Form 8.2 High2024-10-20
CVE-2024-49622 WordPress Apa Banner Slider plugin <= 1.0.0 - CSRF to SQL Injection vulnerability — Apa Banner Slider 8.2 High2024-10-20
CVE-2023-6243 EventON PRO - WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email — EventON (Pro) - WordPress Virtual Event Calendar Plugin 4.3 Medium2024-10-19
CVE-2024-10040 Infinite-Scroll <= 2.6.2 - Cross-Site Request Forgery to Plugin Settings Update — Infinite-Scroll 5.3 Medium2024-10-18
CVE-2024-49220 WordPress Cookie Scanner plugin <= 1.1 - CSRF to Stored XSS vulnerability — Cookie Scanner 7.1 High2024-10-17
CVE-2024-49221 WordPress cSlider plugin <= 2.4.2 - CSRF to Stored XSS vulnerability — cSlider 7.1 High2024-10-17
CVE-2024-49223 WordPress CJ Change Howdy plugin <= 3.3.1 - CSRF to Stored XSS vulnerability — CJ Change Howdy 7.1 High2024-10-17
CVE-2024-49237 WordPress Ahmeti Wp Timeline plugin <= 5.1 - CSRF to Stored XSS vulnerability — Ahmeti Wp Timeline 7.1 High2024-10-17
CVE-2024-49304 WordPress Pinpoint Booking System plugin <= 2.9.9.5.7 - CSRF to Stored Cross Site Scripting (XSS) vulnerability — Pinpoint Booking System 5.4 Medium2024-10-17
CVE-2024-49313 WordPress VKontakte Wall Post plugin <= 2.0 - Cross Site Scripting (XSS) vulnerability — VKontakte Wall Post 7.1 High2024-10-17
CVE-2024-48048 WordPress Wsify Widget plugin <= 1.0 - CSRF to Stored XSS vulnerability — Wsify Widget 7.1 High2024-10-17
CVE-2024-48031 WordPress Featured Posts with Multiple Custom Groups (FPMCG) plugin <= 4.0 - Cross-Site Request Forgery (CSRF) vulnerability — Featured Posts with Multiple Custom Groups (FPMCG) 6.5 Medium2024-10-17
CVE-2024-48037 WordPress Contact Form Widget plugin <= 1.4.2 - CSRF vulnerability — Contact Form Widget 5.4 Medium2024-10-17
CVE-2024-48038 WordPress wp-Monalisa plugin <= 6.4 - Cross Site Request Forgery (CSRF) vulnerability — wp-Monalisa 4.3 Medium2024-10-17
CVE-2024-48047 WordPress Linked Variation for WooCommerce plugin <= 1.0.5 - Cross Site Request Forgery (CSRF) vulnerability — Linked Variation for WooCommerce 4.3 Medium2024-10-17
CVE-2024-9352 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder 4.3 Medium2024-10-17
CVE-2024-9351 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder 4.3 Medium2024-10-17
CVE-2024-20421 Cisco ATA 190 Series Analog Telephone Adapter Firmware Cross-Site Request Forgery Vulnerability — Cisco Analog Telephone Adaptor (ATA) Software 7.1 High2024-10-16
CVE-2024-45693 Apache CloudStack: Request origin validation bypass makes account takeover possible — Apache CloudStack 8.0 High2024-10-16
CVE-2024-8507 File Manager Pro <= 8.3.9 - Cross-Site Request Forgery to Arbitrary File Upload — File Manager Pro 8.8 High2024-10-16
CVE-2020-36839 WP Lead Plus X <= 0.99 - Cross-Site Request Forgery — WordPress Landing Page – Squeeze Page – Responsive Landing Page Builder Free – WP Lead Plus X 8.3 High2024-10-16
CVE-2020-36836 WP Fastest Cache <= 0.9.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion — WP Fastest Cache – WordPress Cache Plugin 8.0 High2024-10-16
CVE-2024-9649 WP ULike <= 4.7.4 - Cross-Site Request Forgery to Statistic Deletion — WP ULike – Like & Dislike Buttons for Engagement and Feedback 4.3 Medium2024-10-16
CVE-2024-49340 IBM Watson Studio Local cross-site request forgery — Watson Studio Local 4.3 Medium2024-10-15
CVE-2024-48913 Hono vulnerable to bypass of CSRF Middleware by a request without Content-Type header. — hono 5.9 Medium2024-10-15
CVE-2024-45737 Maintenance mode state change of App Key Value Store (KVStore) through Cross-Site Request Forgery (CSRF) — Splunk Enterprise 4.3 Medium2024-10-14
CVE-2024-46911 Apache Roller: Weakness in CSRF protection allows privilege escalation — Apache Roller 8.8AIHighAI2024-10-14
CVE-2024-6959 Denial of Service (DOS) in multipart boundary while uploading file in parisneo/lollms-webui — parisneo/lollms-webui 7.5 -2024-10-13
CVE-2024-9778 ImagePress – Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update — ImagePress – Image Gallery 4.3 Medium2024-10-12
CVE-2024-9592 Easy PayPal Gift Certificate <= 1.2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_options — Easy PayPal Gift Certificate 6.1 Medium2024-10-12

Vulnerabilities classified as CWE-352 (跨站请求伪造(CSRF)) represent 4756 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.