CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,328 vulnerabilities with CWE-352
CVE-2025-30908 HIGH
Shamalli Web Directory Free <1.7.6 - CSRF
CVSS 7.1
CVE-2025-2299 MEDIUM
LuckyWP Table of Contents <= 2.1.10 - Cross-Site Request Forgery via ajaxEdit Function
CVSS 6.1
CVE-2025-3150 MEDIUM
itning Student Homework Management System < 1.2.7 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-3153 MEDIUM
Concrete CMS < 8.5.20 and 9.0.0-9.4.0RC2 - Cross-Site Request Forgery and Cross-Site Scripting in Address Attribute
CVSS 6.5
CVE-2025-31723 MEDIUM
Jenkins Simple Queue Plugin <1.4.6 - CSRF
CVSS 4.3
CVE-2025-3099 MEDIUM
WordPress Advanced Search by My Solr Server <2.0.5 - CSRF
CVSS 6.1
CVE-2025-31753 MEDIUM
Animesh Kumar Advanced Speed Increaser - CSRF
CVSS 4.3
CVE-2025-31908 HIGH
Sami Ahmed Siddiqui JSON Structuring Markup - CSRF
CVSS 7.1
CVE-2025-31906 HIGH
ProfitShare.ro WP Profitshare <1.4.9 - CSRF/XSS
CVSS 7.1
CVE-2025-31904 HIGH
Ebook Downloader <= 1.0 - Cross-Site Request Forgery
CVSS 7.1
CVE-2025-31888 MEDIUM
WPExperts.io WP Multistore Locator <2.5.2 - CSRF
CVSS 4.3
CVE-2025-31880 MEDIUM
Stylemix Pearl < 1.3.9 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-31859 MEDIUM
Feedbucket - Website Feedback Tool <1.0.6 - CSRF
CVSS 5.4
CVE-2025-31852 MEDIUM
N-Media Bulk Product Sync <8.6 - CSRF
CVSS 4.3
CVE-2025-31845 MEDIUM
Rohit Choudhary Theme Duplicator - CSRF
CVSS 4.3
CVE-2025-31840 MEDIUM
digireturn Simple Fixed Notice <1.6 - CSRF
CVSS 4.3
CVE-2025-31839 MEDIUM
digireturn DN Footer Contacts <1.8 - CSRF
CVSS 4.3
CVE-2025-31828 MEDIUM
alextselegidis Easy!Appointments <1.4.2 - CSRF
CVSS 4.3
CVE-2025-31814 MEDIUM
OwnerRez API <= 1.2.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-31809 MEDIUM
Labinator Content Types Duplicator <1.1.3 - CSRF
CVSS 4.3
CVE-2025-31808 MEDIUM
SCSS WP Editor <= 1.2.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-31807 MEDIUM
CloudRedux Product Notices for WooCommerce <1.3.3 - CSRF
CVSS 4.3
CVE-2025-31785 MEDIUM
Clearbit Reveal <= 1.0.6 - Cross-Site Request Forgery
CVSS 5.4
CVE-2025-31784 MEDIUM
Embed Extended < 1.4.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-31779 MEDIUM
Query Wrangler <= 1.5.54 - Cross-Site Request Forgery
CVSS 5.4
Details
Vulnerabilities 9,328
Exploit Likelihood Medium