CWE-352
9,678 CVEs • Abstraction: Compound • Likelihood of Exploit: Medium
Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
CVEs (9,678)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the queue_posts fun...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the uucss_update_ru...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the attach_rule fun...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ucss_connect fu...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the ajax_deactivate...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This is due to missing or incorrect nonce validation on the clear_uucss_log...Show more |
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections. |
NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.1` have been found to be subject to an authentication vulnerability. A...Show more |
The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it poss...Show more |
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.3.9. This is due to missing nonce validation on the backup_guard_get_import...Show more |
The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiating an object in the prompt_dismiss_notice action and also lacks CSRF check in the related action. Thi...Show more |
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90. |
1Wpovernight 1Woocommerce Pdf Invoices& Packing Slips Jun 17, 2026 Mar 1, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss. |
1Villatheme 1Cart All In One For Woocommerce Jun 17, 2026 Mar 1, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading to cart modification. |
1Wptrio 1Conditional Shipping For Woocommerce Jun 17, 2026 Mar 1, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activation/deactivation of plugin rulesets. |
1Hasthemes 1Woolentor Woocommerce Elementor Addons + Builder Jun 17, 2026 Mar 1, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change. |
Cross-Site Request Forgery (CSRF) vulnerability in Conversios All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin <= 5.2.3 leads to plugin settings change. |
Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries hierarchy change, included plugin deactivate & activate. |
1Mercadopago 1Mercado Pago Payments For Woocommerce Jun 17, 2026 Mar 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1. |
Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading to plugin settings change. |