Weaknesses of type CWE-352

6,098 results

Falta de verificação de intenção do usuário (CSRF)

A aplicação não consegue confirmar se uma requisição legítima e bem-formada foi realmente intencionada pelo usuário que a enviou. Um atacante pode forjar requisições em nome de um usuário autenticado, fazendo-o executar ações sem consentimento. Isso ocorre porque a aplicação confia apenas em cookies de sessão, sem validar a origem ou intenção real da ação.

Example

Um usuário logado em seu banco acessa um site malicioso enquanto a sessão está ativa. O site injeta uma requisição silenciosa transferindo dinheiro da conta do usuário. Como o navegador envia automaticamente os cookies da sessão, a requisição é aceita como legítima pela aplicação do banco.

How to mitigate

Implemente tokens CSRF únicos e vinculados à sessão em formulários e requisições críticas (POST, PUT, DELETE). Valide a origem da requisição via verificação de header Referer/Origin e use o padrão SameSite nos cookies de sessão. Exija reautenticação para operações sensíveis.

CVE-2026-81912MEDIUMConcrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups featureEPSS 0.2%CVE-2024-31943MEDIUMWordPress USPS Shipping for WooCommerce plugin <= 1.9.2 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2024-51679HIGHWordPress Appointmind plugin <= 4.0.0 - CSRF to Stored XSS vulnerabilityEPSS 0.2%CVE-2025-32268MEDIUMWordPress QR Code Tag for WC plugin <= 1.9.42 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2026-61097CRITICALVulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). EPSS 0.2%CVE-2024-34806MEDIUMWordPress Clearfy Cache plugin <= 2.2.1 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2026-39371HIGHRedwoodSDK has a CSRF vulnerability in server function dispatch via GET requestsEPSS 0.2%CVE-2026-11106MEDIUMInappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafEPSS 0.2%CVE-2025-25128HIGHWordPress Facilita Form Tracker plugin <= 1.0 - CSRF to Stored XSS vulnerabilityEPSS 0.2%CVE-2026-1447MEDIUMMail Mint <= 1.19.2 - Cross-Site Request Forgery to Stored Cross-Site ScriptingEPSS 0.2%CVE-2024-27194HIGHWordPress Fontific plugin <= 0.1.6 - CSRF to XSS vulnerabilityEPSS 0.2%CVE-2026-11270MEDIUMInappropriate implementation in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data viEPSS 0.2%CVE-2025-29722MEDIUMA CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue EPSS 0.2%CVE-2024-37469MEDIUMWordPress Blocksy theme <= 1.9.5 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2026-8417HIGHConcrete CMS 9.5.0 and below is vulnerable to CSRF in do_update() in the package update controllerEPSS 0.2%CVE-2024-0555MEDIUMCross-Site Request Forgery (CSRF) vulnerability on WIC1200EPSS 0.2%CVE-2026-8428HIGHCSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and belowEPSS 0.2%CVE-2024-26450MEDIUMAn issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a CrossEPSS 0.2%CVE-2025-21576MEDIUMVulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Supported versions thaEPSS 0.2%CVE-2025-32575HIGHWordPress WP w3all phpBB Plugin <= 2.9.9 - CSRF to Stored XSS vulnerabilityEPSS 0.2%