Falhas do tipo CWE-352

6.076 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2023-25973MEDIUMWordPress Auto Affiliate Links Plugin <= 6.3.0.2 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2025-23044MEDIUMCross-Site Request Forgery (CSRF) allows creating admin account with POST requestEPSS 0.2%CVE-2022-38716MEDIUMWordPress Motors – Car Dealer & Classified Ads Plugin <= 1.4.4 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2023-25473MEDIUMWordPress Flickr Justified Gallery Plugin <= 3.5 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2025-43745MEDIUMA CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2EPSS 0.2%CVE-2023-35096MEDIUMWordPress myCred Plugin <= 2.5 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2022-45371MEDIUMWordPress ShopEngine Plugin <= 4.1.1 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2023-34373MEDIUMWordPress Zephyr Project Manager Plugin <= 3.3.93 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2026-13826MEDIUMInappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2023-37973MEDIUMWordPress Replace Word Plugin <= 2.1 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2026-82712HIGHTycon Systems TPDIN-Monitor-WEB3 Cross-Site Request ForgeryEPSS 0.2%CVE-2023-37974MEDIUMWordPress WP-FB-AutoConnect Plugin <= 4.6.1 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2026-13887MEDIUMInappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renEPSS 0.2%CVE-2024-40455LOWAn arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.EPSS 0.2%CVE-2023-37386MEDIUMWordPress Media Library Helper by Codexin Plugin <= 1.2.0 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2023-37996MEDIUMWordPress GTmetrix for WordPress Plugin <= 0.4.7 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2023-39923MEDIUMWordPress The Post Grid Plugin <= 7.2.7 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2023-25481MEDIUMWordPress Podlove Subscribe button Plugin <= 1.3.7 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2023-35781MEDIUMWordPress LWS Cleaner Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2025-2042MEDIUMhuang-yk student-manage cross-site request forgeryEPSS 0.2%