Cyber Resilience

CWE · MITRE source

CWE-352Cross-Site Request Forgery (CSRF)

Abstraction: Compound · CVEs in our corpus: 9,586

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Last updated: 22 August 2026 20:22 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 2 mapping(s) from 1 framework(s): CAPEC 2 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A01:2025 Broken Access Control.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • AT-2 Literacy Training and Awareness
  • IA-11 Re-authentication
  • PM-14 Testing, Training, and Monitoring
  • SI-4 System Monitoring
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V3.3.2
  • V3.5.1
  • V10.2.1

NIST 800-53 r5 controls that address this weakness (4)AI-assisted

Control Title Family Why it addresses this CWE
AT-2Literacy Training and AwarenessATAwareness training educates users on avoiding untrusted links and actions that can be exploited via CSRF.
IA-11Re-authenticationIARequiring user re-entry of credentials for sensitive actions prevents automated forgery of requests without active user participation.
PM-14Testing, Training, and MonitoringPMSecurity testing regimens explicitly include checks for missing or ineffective anti-CSRF protections in web applications.
SI-4System MonitoringSIDetects anomalous request patterns consistent with cross-site request forgery.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-10181 KEV 9.99.80.14672020-03-11
CVE-2016-6277 KEV 9.28.80.99782016-12-14
CVE-2025-62593 KEV 9.28.80.01002025-11-26
CVE-2018-7700 9.18.80.74522018-03-27
CVE-2022-41622 9.18.80.87992022-12-07
CVE-2014-100005 KEV 8.78.00.42412015-01-13
CVE-2019-16667 8.78.80.54542019-09-26
CVE-2022-1020 8.79.80.25942022-04-18
CVE-2023-2533 KEV 8.68.40.29252023-06-20
CVE-2025-54782 8.68.80.49992025-08-02
CVE-2019-9787 8.48.80.40792019-03-14
CVE-2019-10655 8.49.80.15472019-03-30
CVE-2022-1574 8.39.80.12022022-06-27
CVE-2017-1000479 8.28.80.32772018-01-03
CVE-2019-0235 8.28.80.32752020-04-30
CVE-2022-27226 8.18.80.30652022-03-19
CVE-2023-48292 8.19.60.22942023-11-20
CVE-2017-16780 8.09.80.05772017-11-10
CVE-2019-17495 8.09.80.05732019-10-10
CVE-2013-3568 8.08.80.25132020-02-06
CVE-2021-25032 8.09.80.06572022-01-10
CVE-2020-23426 7.89.80.03712021-04-08
CVE-2016-1265 7.79.80.02302017-10-13
CVE-2017-9414 7.78.80.15402018-02-05
CVE-2019-7262 7.78.80.16282019-07-02