Weaknesses of type CWE-352

6,089 results

Falta de verificação de intenção do usuário (CSRF)

A aplicação não consegue confirmar se uma requisição legítima e bem-formada foi realmente intencionada pelo usuário que a enviou. Um atacante pode forjar requisições em nome de um usuário autenticado, fazendo-o executar ações sem consentimento. Isso ocorre porque a aplicação confia apenas em cookies de sessão, sem validar a origem ou intenção real da ação.

Example

Um usuário logado em seu banco acessa um site malicioso enquanto a sessão está ativa. O site injeta uma requisição silenciosa transferindo dinheiro da conta do usuário. Como o navegador envia automaticamente os cookies da sessão, a requisição é aceita como legítima pela aplicação do banco.

How to mitigate

Implemente tokens CSRF únicos e vinculados à sessão em formulários e requisições críticas (POST, PUT, DELETE). Valide a origem da requisição via verificação de header Referer/Origin e use o padrão SameSite nos cookies de sessão. Exija reautenticação para operações sensíveis.

CVE-2023-45270MEDIUMWordPress Pinpoint Booking System Plugin <= 2.9.9.4.0 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2026-8410LOWConcrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/deleteEPSS 0.2%CVE-2024-25914MEDIUMWordPress SMTP Mail Plugin <= 1.3.20 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2024-24884MEDIUMWordPress Contact Form 7 Connector Plugin <= 1.2.2 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2026-78081HIGHJoomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7EPSS 0.2%CVE-2024-5285MEDIUMWP Affiliate Platform < 6.5.2 - Affiliate Deletion via CSRFEPSS 0.2%CVE-2024-42603MEDIUMPligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearallEPSS 0.2%CVE-2025-54052HIGHWordPress Realtyna Organic IDX plugin <= 5.0.0 - Local File Inclusion VulnerabilityEPSS 0.2%CVE-2026-25812CRITICALPlaciPy is Missing CSRF Protection on State-Changing EndpointsEPSS 0.2%CVE-2023-42435MEDIUMCross-Site Request Forgery in DEXMA DEXGateEPSS 0.2%CVE-2026-60639HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-13946MEDIUMInappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origEPSS 0.2%CVE-2026-5918MEDIUMInappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2025-63712MEDIUMCross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows reEPSS 0.2%CVE-2026-60635HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-60664HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-60636HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2024-1954MEDIUMOliver POS – A WooCommerce Point of Sale (POS) <= 2.4.1.8 - Cross-Site Request ForgeryEPSS 0.2%CVE-2026-27741MEDIUMBludit <= 3.16.1 CSRF in Plugin and Theme Management EndpointsEPSS 0.2%CVE-2025-24696MEDIUMWordPress Gutenberg Blocks and Page Layouts Plugin <= 1.9.6 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%