Threadlinqs IntelligenceStart free

Weakness · CompoundCWE-352

CWE-352: Cross-Site Request Forgery (CSRF)

Likelihood of exploit: MediumKEV-linkedCompound

As of 2026-10-05, CWE-352 (CSRF) underlies 12 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 23 tracked threats. MITRE rates its likelihood of exploit as Medium.

CVEs
12Mapped to CWE-352
CISA KEV
2Exploited in the wild
Critical
0CVSS v3 critical CVEs
Threats
23Tracked campaigns citing it
Likelihood
MediumMITRE likelihood of exploit

Last updated:

What is CWE-352?

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

CWE-352 is a compound-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific; Technology: Web Based; Technology: Web Server.

Source: MITRE CWE (CWE-352 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality, Integrity, Availability, Non-Repudiation, Access Control — Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Application Data, Modify Application Data, DoS: Crash, Exit, or Restart. The consequences will vary depending on the nature of the functionality that is vulnerable to CSRF. An attacker could trick a client into making an unintentional request to the web server via a URL, image load, XMLHttpRequest, etc., which would then be treated as an authentic request from the client - effectively performing any operations as the victim, leading to an exposure of data, unintended code execution, etc. If the victim is an administrator or privileged user, the consequences may…

Source: MITRE CWE, common consequences.

How CWE-352 is exploited in the wild

Threadlinqs maps 12 CVEs to CWE-352, published between 2008-09-18 and 2026-09-25. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 5 high, 6 medium. The highest EPSS score in the set is 12.0% (CVE-2008-4128), the modelled probability of exploitation in the next 30 days. 23 tracked threats reference CWE-352 directly or through a CVE it covers; the most recent is “Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account Creation (v4.3.0-4.3.1)” (2026-09-26). Affected products concentrate in Cisco (1), DevItems (1), Elementor (1), among 11 vendors in total.

Vulnerabilities (CVEs)

All 12 CVEs mapped to CWE-352, CISA KEV first, then by CVSS score.

Affected vendors

  • Cisco — 1 CVE
  • DevItems — 1 CVE
  • Elementor — 1 CVE
  • GitLab — 1 CVE
  • Rizwan17 — 1 CVE
  • Saad Iqbal — 1 CVE
  • Splunk — 1 CVE
  • hedgedoc — 1 CVE
  • jeremyevans — 1 CVE
  • properfraction — 1 CVE
  • ray-project — 1 CVE

Threat activity

23 tracked threats cite CWE-352:

Mitigations

  • Architecture and Design / Libraries or Frameworks: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, use anti-CSRF packages such as the OWASP CSRFGuard. [REF-330] Another example is the ESAPI Session Management control, which includes a component for CSRF. [REF-45]
  • Implementation: Ensure that the application is free of cross-site scripting issues (CWE-79), because most CSRF defenses can be bypassed using attacker-controlled script.
  • Architecture and Design: Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330). [REF-332]
  • Architecture and Design: Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.
  • Architecture and Design: Use the "double-submitted cookie" method as described by Felten and Zeller: When a user visits a site, the site should generate a pseudorandom value and set it as a cookie on the user's machine. The site should require every form submission to include this value as a form value and also as a cookie value. When a POST request is sent to the site, the request should only be considered valid if the form value and the cookie value are the same. Because of the same-origin policy, an attacker cannot read or modify the value stored in the cookie. To successfully submit a form on behalf of the user, the attacker would have to correctly guess the pseudorandom value. If the pseudorandom value is…
  • Architecture and Design: Do not use the GET method for any request that triggers a state change.
  • Implementation: Check the HTTP Referer header to see if the request originated from an expected page. This could break legitimate functionality, because users or proxies may have disabled sending the Referer for privacy reasons.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Manual Analysis (effectiveness: High): This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. Specifically, manual analysis can be useful for finding this weakness, and for minimizing false positives assuming an understanding of business logic. However, it might not achieve desired code coverage within limited time constraints. For black-box analysis, if credentials…
  • Automated Static Analysis (effectiveness: Limited): CSRF is currently difficult to detect reliably using automated techniques. This is because each application has its own implicit security policy that dictates which requests can be influenced by an outsider and automatically performed on behalf of a user, versus which requests require strong confidence that the user intends to make the request. For example, a keyword search of the public portion of a web site is typically expected to be encoded within a link that can be launched automatically…
  • Automated Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Bytecode Weakness Analysis - including disassembler + source code weakness analysis Binary Weakness Analysis - including disassembler + source code weakness analysis
  • Manual Static Analysis - Binary or Bytecode (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Binary / Bytecode disassembler - then use manual analysis for vulnerabilities & anomalies
  • Dynamic Analysis with Automated Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Web Application Scanner
  • Dynamic Analysis with Manual Results Interpretation (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Fuzz Tester Framework-based Fuzzer
  • Manual Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Focused Manual Spotcheck - Focused manual analysis of source Manual Source Code Review (not inspections)
  • Automated Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.