Falhas do tipo CWE-352

6.073 resultados

Falsificação de Solicitação entre Sites (CSRF)

A aplicação web não valida adequadamente se uma requisição legítima foi realmente originada da intenção do usuário autenticado, ou se foi forjada por um atacante. Um site malicioso consegue fazer seu navegador enviar requisições em seu nome para a aplicação vulnerável, executando ações sem seu consentimento explícito.

Exemplo

Um usuário logado em seu banco recebe um email com um link ou imagem oculta que, ao ser acessado, força seu navegador a enviar uma requisição para transferir dinheiro — a aplicação processa a transferência porque reconhece o cookie de sessão válido, mas nunca verificou se o usuário realmente quis fazer isso.

Como mitigar

Implemente tokens CSRF únicos por sessão (gerados no servidor, incluídos em formulários e validados antes de processar) e use atributos SameSite em cookies de sessão. Para APIs, valide headers customizados como X-Requested-With e implemente CORS restritivo.

CVE-2024-0433MEDIUMGestpay for WooCommerce <= 20221130 - Cross-Site Request Forgery (CSRF) via ajax_unset_default_cardEPSS 0.3%CVE-2023-23726MEDIUMWordPress Tickera – WordPress Event Ticketing plugin <= 3.5.1.0 - CSRF Leading To Post Status Change VulnerabilityEPSS 0.3%CVE-2021-36855MEDIUMWordPress Booking Ultra Pro plugin <= 1.1.4 - Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerabilityEPSS 0.3%CVE-2026-12986HIGHA critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows thEPSS 0.3%CVE-2023-50923MEDIUMIn QUIC in RFC 9000, the Latency Spin Bit specification (section 17.4) does not strictly constrain the bit value when the feature is disableEPSS 0.3%CVE-2023-25832HIGHBUG-000148346 There is a Cross-Site Request Forgery (CSRF) vulnerability in Portal for ArcGIS.EPSS 0.3%CVE-2026-34613MEDIUMAVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security PluginsEPSS 0.3%CVE-2022-46491MEDIUMA Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allows attackers to arbiEPSS 0.3%CVE-2024-27955HIGHWordPress Automatic plugin <= 3.92.0 - CSRF to Privilege Escalation vulnerabilityEPSS 0.3%CVE-2024-23831HIGHPrivilege escalation through CSRF attack on 'setup.pl'EPSS 0.3%CVE-2023-52150HIGHWordPress Dynamic Content for Elementor Plugin < 2.12.5 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2024-9990HIGHCrypto <= 2.15 - Cross-Site Request Forgery to Authentication BypassEPSS 0.3%CVE-2025-5766MEDIUMcode-projects Laundry System cross-site request forgeryEPSS 0.3%CVE-2025-4327MEDIUMMRCMS cross-site request forgeryEPSS 0.3%CVE-2023-23802MEDIUMWordPress HT Easy GA4 ( Google Analytics 4 ) Plugin <= 1.0.6 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-2440HIGHUserPro <= 5.1.1 - Cross-Site Request Forgery to Privilege EscalationEPSS 0.3%CVE-2022-45376MEDIUMWordPress Side Cart Woocommerce (Ajax) Plugin < 2.1 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-24414MEDIUMWordPress Robo Gallery Plugin <= 3.2.11 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2023-1205HIGHNETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly imEPSS 0.3%CVE-2023-25449MEDIUMWordPress CformsII Plugin <=15.0.4 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%