On this page

CWE-352: Cross-Site Request Forgery (CSRF)

Weakness Summary

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

  • Canonical source: MITRE CWE-352 (opens in a new tab)
  • Published Atomicorp CVE observations: 42
  • Distinct affected products in those observations: 41
  • Active Atomicorp rules associated with this weakness: 77

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2022-1574WordPress HTML2WP <=1.0.0 - Arbitrary File Uploadhtml2wpAttack Blocked by Atomicorp382238
CVE-2026-53649Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEjoroAttack Blocked by Atomicorp340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-54782NestJS DevTools Integration - Remote Code Executiondevtools-integrationAttack Blocked by Atomicorp345240
CVE-2025-62593Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding AttackrayAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2016-4808Web2py 2.14.5 - Multiple Vulnerabilitiesweb2pyAttack Blocked by Atomicorp344360 , 344364 , 344366 , 344370
CVE-2016-6277NETGEAR Routers - Remote Code Executiond6220 firmwareAttack Blocked by Atomicorp347009
CVE-2017-9413Subsonic 6.1.1 - Server-Side Request ForgerysubsonicAttack Blocked by Atomicorp390726 , 392301 , 392647 , 392648
CVE-2017-9810Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilitiesanti-virus for linux serverAttack Blocked by Atomicorp390704 , 390724
CVE-2018-11442EasyService Billing 1.0 - Cross-Site Request Forgeryeasyservice billingAttack Blocked by Atomicorp340147 , 340148 , 340149 , 341245 , 341256 , 342259 , 344361 , 344362 , 344363 , 344370 , 345490 , 345493 , 350147
CVE-2018-11445EasyService Billing 1.0 - Cross-Site Request Forgeryeasyservice billingAttack Blocked by Atomicorp340147 , 340148 , 340149 , 341245 , 341256 , 342259 , 344361 , 344362 , 344363 , 344370 , 345490 , 345493 , 350147
CVE-2018-1213Dell EMC Isilon OneFS - Multiple Vulnerabilitiesemc isilon onefsAttack Blocked by Atomicorp330791 , 333141 , 340147 , 340148 , 340152 , 341256 , 342259 , 346755 , 390585
CVE-2018-15884RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)mp c4504ex firmwareAttack Blocked by Atomicorp350147
CVE-2018-6224Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilitiesemail encryption gatewayAttack Blocked by Atomicorp333141 , 337209 , 337210 , 337211 , 340145 , 340147 , 340148 , 340149 , 340156 , 341145 , 341245 , 341256 , 342259 , 344370 , 346755 , 350147 , 390572 , 390585 , 390704
CVE-2018-7700DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code ExecutiondedecmsAttack Blocked by Atomicorp344370
CVE-2020-5776MAGMI - Cross-Site Request ForgerymagmiAttack Blocked by Atomicorp344364 , 344366 , 344370 , 345490
CVE-2020-7991Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)frameworkAttack Blocked by Atomicorp340147 , 340148 , 342259 , 345490 , 345493 , 346755 , 350147 , 350148 , 398001
CVE-2021-25052WordPress Button Generator <2.3.3 - Remote File Inclusionbutton generatorAttack Blocked by Atomicorp340464 , 340465
CVE-2021-46398FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)filebrowserAttack Blocked by Atomicorp345490 , 345493
CVE-2022-0439Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injectionemail subscribers &amp; newslettersAttack Blocked by Atomicorp340016 , 377360 , 380122
CVE-2022-25241FileCloud 21.2 - Cross-Site Request Forgery (CSRF)filecloudAttack Blocked by Atomicorp345490
CVE-2023-23897Ozette Plugins - Cross-Site Request Forgerysimple mobile url redirectAttack Blocked by Atomicorp345490 , 377360
CVE-2025-56798Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier Cross-Site Request Forgery VulnerabilityLime Technology, Inc.'s Unraid OS version 6.12.14 and earlierAttack Blocked by Atomicorp333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 393655
CVE-2026-60009theia Arbitrary Code Execution VulnerabilitytheiaAttack Blocked by Atomicorp351000
CVE-2026-73222Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (–studio)claude-code-templatesAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34228Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File WriteemlogAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-49471Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCEserenaAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2020-36836WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletionwp fastest cacheAttack Blocked by Atomicorp340748 , 347006 , 377360
CVE-2026-14234WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRFWOLFAttack Blocked by Atomicorp340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-14239Tourmaster < 5.4.8 - Stored XSS via CSRFtourmasterAttack Blocked by Atomicorp333141 , 340087 , 340095 , 340099 , 340148 , 341099 , 341266 , 346755
CVE-2011-4452WikkaWiki 1.3.2 - Multiple VulnerabilitieswikkawikiAttack Blocked by Atomicorp331702 , 340007 , 344360 , 344361 , 344362 , 344363 , 344370 , 360152 , 390715 , 390726 , 392647
CVE-2012-0286stoneware webnetwork6 - Multiple VulnerabilitieswebnetworkAttack Blocked by Atomicorp390726 , 392301 , 392647 , 392648
CVE-2012-5683ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password ResetzpanelAttack Blocked by Atomicorp340016 , 340017 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 360147 , 360148 , 390704
CVE-2014-0864IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limitsAttack Blocked by Atomicorp392301
CVE-2015-2755WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scriptingab google map travelAttack Blocked by Atomicorp346755 , 377360
CVE-2013-4865MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilitiesveralite firmwareAttack Blocked by Atomicorp330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2018-18760RhinOS CMS 3.x - Arbitrary File DownloadrhinosAttack Blocked by Atomicorp334168 , 344360
CVE-2019-12616phpMyAdmin 4.8 - Cross-Site Request ForgeryphpmyadminAttack Blocked by Atomicorp390727 , 392301 , 392648
CVE-2020-8615Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgerytutor lmsAttack Blocked by Atomicorp345490 , 377360
CVE-2021-24947WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Readresponsive vector mapsAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2025-47204Bootstrap Multiselect <= 1.1.2 - Cross-Site Scriptingbootstrap multiselectAttack Blocked by Atomicorp340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-89148AVideo Open Redirect via playlistSort.php Referer HeaderAVideoAttack Blocked by Atomicorp340162 , 340163 , 340165 , 344365
CVE-2022-29495WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgerypopup builderAttack Blocked by Atomicorp345490 , 377360

Associated Atomicorp WAF Rules

RuleStatusBehavior
330791Activedisruptive (deny)
331702Activedisruptive (deny)
333140Activedisruptive (deny)
333141Activedisruptive (deny)
334168Activedisruptive (deny)
337209Activedisruptive (deny)
337210Activedisruptive (deny)
337211Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340087Activedisruptive (deny)
340095Activedisruptive (deny)
340099Activedisruptive (deny)
340121Activedisruptive (deny)
340145Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340149Activedisruptive (deny)
340152Activedisruptive (deny)
340156Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
340193Activedisruptive (deny)
340464Activedisruptive (deny)
340465Activedisruptive (deny)
340748Activedisruptive (deny)
341099Activedisruptive (deny)
341145Activedisruptive (deny)
341245Activedisruptive (deny)
341256Activedisruptive (deny)
341266Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344362Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
345240Activedisruptive (deny)
345490Activedisruptive (deny)
345491Activenon-disruptive (pass)
345492Activenon-disruptive (pass)
345493Activenon-disruptive (pass)
346755Activedisruptive (deny)
347006Activedisruptive (deny)
347009Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
351000Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
360152Activedisruptive (deny)
377360Activenon-disruptive (pass)
380122Activedisruptive (deny)
382238Activedisruptive (deny)
390572Activedisruptive (deny)
390585Activedisruptive (deny)
390636Activedisruptive (deny)
390704Activedisruptive (deny)
390709Activedisruptive (deny)
390715Activedisruptive (deny)
390724Activedisruptive (deny)
390726Activedisruptive (deny)
390727Activedisruptive (deny)
390904Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
393655Activedisruptive (deny)
398001Activenon-disruptive (pass)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-111 (opens in a new tab) , CAPEC-462 (opens in a new tab) , CAPEC-467 (opens in a new tab) , CAPEC-62 (opens in a new tab)