Falhas do tipo CWE-352

6.081 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2025-8592HIGHInspiro <= 2.1.2 - Cross-Site Request Forgery to Arbitrary Plugin InstallationEPSS 0.2%CVE-2026-94404HIGHMISP CSRF vulnerability allows unauthorized attribute modificationEPSS 0.2%CVE-2023-46775MEDIUMWordPress Original texts Yandex WebMaster Plugin <= 1.18 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2024-32435MEDIUMWordPress AffiEasy plugin <= 1.1.4 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2023-46085MEDIUMWordPress Wp Ultimate Review Plugin <= 2.2.4 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.2%CVE-2026-60636HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2026-25812CRITICALPlaciPy is Missing CSRF Protection on State-Changing EndpointsEPSS 0.2%CVE-2025-24568MEDIUMWordPress Starter Templates plugin <= 4.4.9 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2026-13946MEDIUMInappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origEPSS 0.2%CVE-2024-1954MEDIUMOliver POS – A WooCommerce Point of Sale (POS) <= 2.4.1.8 - Cross-Site Request ForgeryEPSS 0.2%CVE-2025-24696MEDIUMWordPress Gutenberg Blocks and Page Layouts Plugin <= 1.9.6 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2024-42606MEDIUMPligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1EPSS 0.2%CVE-2024-32449MEDIUMWordPress RestroPress plugin <= 3.1.2 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2025-54052HIGHWordPress Realtyna Organic IDX plugin <= 5.0.0 - Local File Inclusion VulnerabilityEPSS 0.2%CVE-2025-63712MEDIUMCross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows reEPSS 0.2%CVE-2026-60633HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2024-10045MEDIUMTransients Manager <= 2.0.6 - Cross-Site Request ForgeryEPSS 0.2%CVE-2025-20322MEDIUMDenial of Service (DoS) in Search Head Cluster through Cross-Site Request Forgery (CSRF) in Splunk EnterpriseEPSS 0.2%CVE-2026-13952MEDIUMInappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data EPSS 0.2%CVE-2026-60635HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%