CWE Top 25 Most Dangerous Software Weaknesses (2024)
CWE Top 25 2024: Access Control and Authorization

CWE Top 25 Most Dangerous Software Weaknesses (2024) CWE-352: Cross-Site Request Forgery (CSRF)

Rank 4 in the 2024 CWE Top 25 (frequency x severity of CVEs). The web application does not verify that a state-changing request was intentionally sent by the user, allowing an attacker to force the victim's browser to submit requests.

Other controls in CWE Top 25 2024: Access Control and Authorization

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.