CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,347 vulnerabilities with CWE-352
CVE-2024-32434 MEDIUM
Tyche Softwares Order Delivery Date for WooCommerce - CSRF
CVSS 4.3
CVE-2024-32433 MEDIUM
Themefic BEAF <= 4.5.4 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32141 MEDIUM
Libsyn Publisher Hub <= 1.4.4 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32104 MEDIUM
XLPlugins NextMove Lite <= 2.18.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32103 MEDIUM
Siteimprove < 2.0.6 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-32102 MEDIUM
Crony Cronjob Manager < 0.5.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32101 MEDIUM
Email Marketing for WooCommerce by Omnisend <= 1.14.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32099 MEDIUM
WP Mail Catcher <= 2.1.6 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32097 MEDIUM
GEO my WordPress < 4.1 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-32096 MEDIUM
WP Migration Plugin DB & Files - WP Synchro - CSRF
CVSS 5.4
CVE-2024-32095 MEDIUM
MultiParcels Shipping For WooCommerce <1.16.9 - CSRF
CVSS 4.3
CVE-2024-32094 MEDIUM
Church Content - Sermons, Events and More <= 2.6 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32093 MEDIUM
Nose Graze Novelist < 1.2.2 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-32092 MEDIUM
Kimili Flash Embed <= 2.5.3 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-32091 MEDIUM
Sangar Slider < 1.3.2 - Cross-Site Request Forgery
CVSS 6.5
CVE-2024-32090 MEDIUM
Andy Moyle Church Admin <4.0.27 - CSRF
CVSS 4.3
CVE-2024-32089 MEDIUM
Supsystic Digital Publications <1.7.7 - CSRF
CVSS 4.3
CVE-2024-32088 MEDIUM
SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd <= 6.15.20 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32085 MEDIUM
AitThemes Citadela Listing <5.20.0 - CSRF
CVSS 5.4
CVE-2024-32084 MEDIUM
Gold Plugins Before And After <= 3.9 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31942 MEDIUM
Calendarista Basic Edition <= 3.0.2 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-31941 MEDIUM
CP Media Player < 1.1.3 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-32452 MEDIUM
WP EasyCart < 5.5.19 - Cross-Site Request Forgery
CVSS 5.4
CVE-2024-32451 MEDIUM
wpWax Legal Pages < 1.4.2 - Cross-Site Request Forgery
CVSS 4.3
CVE-2024-32450 MEDIUM
WpTravelly < 1.6.0 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities 9,347
Exploit Likelihood Medium