CWE-352

Medium likelihood

Cross-Site Request Forgery (CSRF)

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

9,337 vulnerabilities with CWE-352
CVE-2025-23567 HIGH
GDReseller <= 1.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVSS 7.1
CVE-2025-23566 HIGH
Syed Amir Hussain Custom Post <1.0 - CSRF
CVSS 7.1
CVE-2025-23560 HIGH
Elke Hinze, Plumeria Web Design Web Testimonials <1.2 - XSS
CVSS 7.1
CVE-2025-23559 HIGH
MemeOne < 2.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVSS 7.1
CVE-2025-23558 HIGH
digfish Geotagged Media <0.3.0 - XSS
CVSS 7.1
CVE-2025-23557 HIGH
Kathleen Malone Find Your Reps - CSRF
CVSS 7.1
CVE-2025-23537 HIGH
add custom google tag manager <= 1.0.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CVSS 7.1
CVE-2025-23533 HIGH
Adrian Moreno WP Lyrics <0.4.1 - CSRF
CVSS 7.1
CVE-2025-23532 HIGH
MyAnime Widget <= 1.0 - Cross-Site Request Forgery to Privilege Escalation
CVSS 8.8
CVE-2025-23530 HIGH
Custom Post Type Lockdown <2.0 - CSRF
CVSS 8.8
CVE-2025-23513 HIGH
Joshua Wieczorek Bible Embed <0.0.4 - CSRF
CVSS 7.1
CVE-2025-23511 HIGH
Viktoria Rei Bauer WP-BlackCheck <2.7.2 - CSRF
CVSS 7.1
CVE-2025-23510 HIGH
Zaantar WordPress Logging Service <1.5.4 - CSRF
CVSS 7.1
CVE-2025-23508 HIGH
EdesaC Extra Options - Favicons <1.1.0 - XSS
CVSS 7.1
CVE-2025-23501 HIGH
SpruceJoy Cookie Consent & Autoblock - Stored XSS
CVSS 7.1
CVE-2025-23499 HIGH
Pascal Casier Board Election <1.0.1 - XSS
CVSS 7.1
CVE-2025-23497 HIGH
Albdesign Simple Project Manager <1.2.2 - CSRF
CVSS 7.1
CVE-2025-23483 HIGH
Niklas Olsson Universal Analytics Injector - CSRF
CVSS 7.1
CVE-2025-23476 HIGH
isnowfy my-related-posts <1.1 - CSRF
CVSS 7.1
CVE-2025-23471 HIGH
Andy Chapman ECT Add to Cart Button <1.4 - XSS
CVSS 7.1
CVE-2025-23470 HIGH
X Villamuera Visit Site Link enhanced - CSRF
CVSS 7.1
CVE-2025-23467 HIGH
Vimal Ghorecha RSS News Scroller - CSRF
CVSS 7.1
CVE-2025-23463 HIGH
Mukesh Dak MD Custom content - CSRF
CVSS 7.1
CVE-2025-23456 HIGH
Somethinkodd.com Development Team EmailShroud <2.2.1 - CSRF
CVSS 7.1
CVE-2025-23455 HIGH
Mastersoftwaresolutions WP VTiger Synchronization - XSS
CVSS 7.1
Details
Vulnerabilities 9,337
Exploit Likelihood Medium