On this page
CWE-352: Cross-Site Request Forgery (CSRF)
Weakness Summary
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
- Canonical source: MITRE CWE-352 (opens in a new tab)
- Published Atomicorp CVE observations: 42
- Distinct affected products in those observations: 41
- Active Atomicorp rules associated with this weakness: 77
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2022-1574 | WordPress HTML2WP <=1.0.0 - Arbitrary File Upload | html2wp | Attack Blocked by Atomicorp | 382238 |
| CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | joro | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-54782 | NestJS DevTools Integration - Remote Code Execution | devtools-integration | Attack Blocked by Atomicorp | 345240 |
| CVE-2025-62593 | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | ray | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2016-4808 | Web2py 2.14.5 - Multiple Vulnerabilities | web2py | Attack Blocked by Atomicorp | 344360 , 344364 , 344366 , 344370 |
| CVE-2016-6277 | NETGEAR Routers - Remote Code Execution | d6220 firmware | Attack Blocked by Atomicorp | 347009 |
| CVE-2017-9413 | Subsonic 6.1.1 - Server-Side Request Forgery | subsonic | Attack Blocked by Atomicorp | 390726 , 392301 , 392647 , 392648 |
| CVE-2017-9810 | Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities | anti-virus for linux server | Attack Blocked by Atomicorp | 390704 , 390724 |
| CVE-2018-11442 | EasyService Billing 1.0 - Cross-Site Request Forgery | easyservice billing | Attack Blocked by Atomicorp | 340147 , 340148 , 340149 , 341245 , 341256 , 342259 , 344361 , 344362 , 344363 , 344370 , 345490 , 345493 , 350147 |
| CVE-2018-11445 | EasyService Billing 1.0 - Cross-Site Request Forgery | easyservice billing | Attack Blocked by Atomicorp | 340147 , 340148 , 340149 , 341245 , 341256 , 342259 , 344361 , 344362 , 344363 , 344370 , 345490 , 345493 , 350147 |
| CVE-2018-1213 | Dell EMC Isilon OneFS - Multiple Vulnerabilities | emc isilon onefs | Attack Blocked by Atomicorp | 330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585 |
| CVE-2018-15884 | RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin) | mp c4504ex firmware | Attack Blocked by Atomicorp | 350147 |
| CVE-2018-6224 | Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities | email encryption gateway | Attack Blocked by Atomicorp | 333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704 |
| CVE-2018-7700 | DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution | dedecms | Attack Blocked by Atomicorp | 344370 |
| CVE-2020-5776 | MAGMI - Cross-Site Request Forgery | magmi | Attack Blocked by Atomicorp | 344364 , 344366 , 344370 , 345490 |
| CVE-2020-7991 | Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password) | framework | Attack Blocked by Atomicorp | 340147 , 340148 , 342259 , 345490 , 345493 , 346755 , 350147 , 350148 , 398001 |
| CVE-2021-25052 | WordPress Button Generator <2.3.3 - Remote File Inclusion | button generator | Attack Blocked by Atomicorp | 340464 , 340465 |
| CVE-2021-46398 | FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE) | filebrowser | Attack Blocked by Atomicorp | 345490 , 345493 |
| CVE-2022-0439 | Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injection | email subscribers & newsletters | Attack Blocked by Atomicorp | 340016 , 377360 , 380122 |
| CVE-2022-25241 | FileCloud 21.2 - Cross-Site Request Forgery (CSRF) | filecloud | Attack Blocked by Atomicorp | 345490 |
| CVE-2023-23897 | Ozette Plugins - Cross-Site Request Forgery | simple mobile url redirect | Attack Blocked by Atomicorp | 345490 , 377360 |
| CVE-2025-56798 | Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier Cross-Site Request Forgery Vulnerability | Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier | Attack Blocked by Atomicorp | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 393655 |
| CVE-2026-60009 | theia Arbitrary Code Execution Vulnerability | theia | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-73222 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio) | claude-code-templates | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-34228 | Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write | emlog | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-49471 | Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE | serena | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2020-36836 | WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion | wp fastest cache | Attack Blocked by Atomicorp | 340748 , 347006 , 377360 |
| CVE-2026-14234 | WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF | WOLF | Attack Blocked by Atomicorp | 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-14239 | Tourmaster < 5.4.8 - Stored XSS via CSRF | tourmaster | Attack Blocked by Atomicorp | 333141 , 340087 , 340095 , 340099 , 340148 , 341099 , 341266 , 346755 |
| CVE-2011-4452 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | Attack Blocked by Atomicorp | 331702 , 340007 , 344360 , 344361 , 344362 , 344363 , 344370 , 360152 , 390715 , 390726 , 392647 |
| CVE-2012-0286 | stoneware webnetwork6 - Multiple Vulnerabilities | webnetwork | Attack Blocked by Atomicorp | 390726 , 392301 , 392647 , 392648 |
| CVE-2012-5683 | ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset | zpanel | Attack Blocked by Atomicorp | 340016 , 340017 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 360147 , 360148 , 390704 |
| CVE-2014-0864 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | Attack Blocked by Atomicorp | 392301 |
| CVE-2015-2755 | WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting | ab google map travel | Attack Blocked by Atomicorp | 346755 , 377360 |
| CVE-2013-4865 | MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities | veralite firmware | Attack Blocked by Atomicorp | 330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647 |
| CVE-2018-18760 | RhinOS CMS 3.x - Arbitrary File Download | rhinos | Attack Blocked by Atomicorp | 334168 , 344360 |
| CVE-2019-12616 | phpMyAdmin 4.8 - Cross-Site Request Forgery | phpmyadmin | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2020-8615 | Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery | tutor lms | Attack Blocked by Atomicorp | 345490 , 377360 |
| CVE-2021-24947 | WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Read | responsive vector maps | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2025-47204 | Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting | bootstrap multiselect | Attack Blocked by Atomicorp | 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-89148 | AVideo Open Redirect via playlistSort.php Referer Header | AVideo | Attack Blocked by Atomicorp | 340162 , 340163 , 340165 , 344365 |
| CVE-2022-29495 | WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery | popup builder | Attack Blocked by Atomicorp | 345490 , 377360 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 330791 | Active | disruptive (deny) |
| 331702 | Active | disruptive (deny) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 334168 | Active | disruptive (deny) |
| 337209 | Active | disruptive (deny) |
| 337210 | Active | disruptive (deny) |
| 337211 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340087 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340099 | Active | disruptive (deny) |
| 340121 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 340464 | Active | disruptive (deny) |
| 340465 | Active | disruptive (deny) |
| 340748 | Active | disruptive (deny) |
| 341099 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 341266 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 345240 | Active | disruptive (deny) |
| 345490 | Active | disruptive (deny) |
| 345491 | Active | non-disruptive (pass) |
| 345492 | Active | non-disruptive (pass) |
| 345493 | Active | non-disruptive (pass) |
| 346755 | Active | disruptive (deny) |
| 347006 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 351000 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 360152 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380122 | Active | disruptive (deny) |
| 382238 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390585 | Active | disruptive (deny) |
| 390636 | Active | disruptive (deny) |
| 390704 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390715 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398001 | Active | non-disruptive (pass) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-111 (opens in a new tab) , CAPEC-462 (opens in a new tab) , CAPEC-467 (opens in a new tab) , CAPEC-62 (opens in a new tab)