CWE-352 跨站请求伪造(CSRF) 类弱点 4882 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-352 跨站请求伪造是一种身份验证缺陷漏洞,指应用未能充分验证请求是否由用户主动发起。攻击者通常通过诱导用户点击恶意链接或加载隐蔽图片,利用用户已登录的会话状态,以用户身份执行非预期的操作,如转账或修改密码。开发者可通过在请求中添加并验证唯一的 CSRF 令牌、检查 Referer 头以及使用 SameSite Cookie 属性来有效防御此类攻击。
<form action="/url/profile.php" method="post"> <input type="text" name="firstname"/> <input type="text" name="lastname"/> <br/> <input type="text" name="email"/> <input type="submit" name="submit" value="Update"/> </form>// initiate the session in order to validate sessions session_start(); //if the session is registered to a valid user then allow update if (! session_is_registered("username")) { echo "invalid session detected!"; // Redirect user to login page [...] exit; } // The user session is valid, so process the request // and update the information update_profile(); function update_profile { // read in the data from $POST and send an update // to the database SendUpdateToDatabase($_SESSION['username'], $_POST['email']); [...] echo "Your profile has been successfully updated."; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-22784 | WordPress plugin Background Control 跨站请求伪造漏洞 — Background Control | 8.6 | High | 2025-01-15 |
| CVE-2024-55893 | TYPO3 安全漏洞 — typo3 | 4.3 | Medium | 2025-01-14 |
| CVE-2024-55894 | TYPO3 安全漏洞 — typo3 | 4.3 | Medium | 2025-01-14 |
| CVE-2024-55920 | TYPO3 安全漏洞 — typo3 | 4.3 | Medium | 2025-01-14 |
| CVE-2024-55921 | TYPO3 安全漏洞 — typo3 | 7.5 | High | 2025-01-14 |
| CVE-2024-55922 | TYPO3 安全漏洞 — typo3 | 5.4 | Medium | 2025-01-14 |
| CVE-2024-55923 | TYPO3 安全漏洞 — typo3 | 4.3 | Medium | 2025-01-14 |
| CVE-2024-55924 | TYPO3 安全漏洞 — typo3 | 8.0 | High | 2025-01-14 |
| CVE-2024-55945 | TYPO3 安全漏洞 — typo3 | 4.3 | Medium | 2025-01-14 |
| CVE-2025-21193 | Microsoft Active Directory Federation Services 跨站请求伪造漏洞 — Windows Server 2016 | 6.5 | Medium | 2025-01-14 |
| CVE-2025-23081 | Mediawiki DataTransfer Extension 安全漏洞 — Mediawiki - DataTransfer Extension | 9.6 | - | 2025-01-14 |
| CVE-2024-47100 | Siemens SIMATIC S7-1200 跨站请求伪造漏洞 — SIMATIC S7-1200 CPU 1211C AC/DC/Rly | 7.1 | High | 2025-01-14 |
| CVE-2025-0393 | WordPress plugin Royal Elementor Addons and Templates 跨站请求伪造漏洞 — Royal Addons for Elementor – Addons and Templates Kit for Elementor | 6.1 | Medium | 2025-01-14 |
| CVE-2025-22963 | Teedy 安全漏洞 — Teedy | 7.5 | High | 2025-01-13 |
| CVE-2024-6662 | MegaBIP 安全漏洞 — MegaBIP | 8.8 | - | 2025-01-10 |
| CVE-2025-23113 | REDCap 安全漏洞 — REDCap | 3.4 | Low | 2025-01-10 |
| CVE-2024-13304 | Drupal 安全漏洞 — Minify JS | 8.8 | - | 2025-01-09 |
| CVE-2024-13293 | Drupal 安全漏洞 — POST File | 8.8 | - | 2025-01-09 |
| CVE-2024-13284 | Drupal 安全漏洞 — Gutenberg | 8.8 | - | 2025-01-09 |
| CVE-2024-13261 | Drupal 安全漏洞 — Acquia DAM | 8.8 | - | 2025-01-09 |
| CVE-2024-13260 | Drupal 安全漏洞 — Migrate queue importer | 8.8 | - | 2025-01-09 |
| CVE-2024-13250 | Drupal 安全漏洞 — Drupal Symfony Mailer Lite | 8.8 | - | 2025-01-09 |
| CVE-2024-13244 | Drupal 安全漏洞 — Migrate Tools | 8.8 | - | 2025-01-09 |
| CVE-2025-22814 | WordPress plugin Zephyr Admin Theme 跨站请求伪造漏洞 — Zephyr Admin Theme | 7.1 | High | 2025-01-09 |
| CVE-2024-12218 | WordPress plugin Woocommerce check pincode/zipcode for shipping 跨站请求伪造漏洞 — Woocommerce check pincode/zipcode for shipping | 6.1 | Medium | 2025-01-09 |
| CVE-2024-12605 | WordPress plugin AI Scribe 安全漏洞 — Opace AI Scribe: SEO Content Creator & Humaizer for OpenAI & Anthropic | 4.3 | Medium | 2025-01-09 |
| CVE-2024-12206 | WordPress plugin Pearl 跨站请求伪造漏洞 — Pearl – Header Builder | 4.3 | Medium | 2025-01-09 |
| CVE-2024-13203 | E-Commerce-PHP 安全漏洞 — E-Commerce-PHP | 4.3 | Medium | 2025-01-09 |
| CVE-2025-22503 | WordPress plugin Admin debug wordpress – enable debug 跨站请求伪造漏洞 — Admin debug wordpress – enable debug | 4.3 | Medium | 2025-01-07 |
| CVE-2025-22520 | WordPress plugin Tock Widget 跨站请求伪造漏洞 — Tock Widget | 7.1 | High | 2025-01-07 |
CWE-352(跨站请求伪造(CSRF)) 是常见的弱点类别,本平台收录该类弱点关联的 4882 条 CVE 漏洞。