Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 8.8
CVE-2026-66602

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affec…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-55593

Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request valid…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-68923

MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware on…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.4
CVE-2026-66635

Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-19650

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-17608

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.7
CVE-2026-15384

The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that …

Fix unknown
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.3
CVE-2026-67366

Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the fronte…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.8
CVE-2026-73847

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.p…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.1
CVE-2026-57469

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory i…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.7
CVE-2026-72849

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an externa…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.3
CVE-2026-72658

Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to…

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.3
CVE-2026-17069

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF toke…

No fix yet
Fix from $4,900 2026-08-13
Planning Analytics Local MEDIUM 6.5
CVE-2026-13365

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthor…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-73481

phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion …

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73482

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is t…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-67990

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controll…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-19088

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.1
CVE-2026-73423

Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only t…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.4
CVE-2026-48551

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cook…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.3
CVE-2026-73292

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.2
CVE-2026-47228

Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random password for `user_uuid_assigne…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-47229

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-c…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.8
CVE-2026-73222

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --stud…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73162

Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/d…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.3
CVE-2026-19418

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving t…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72578

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actio…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-66642

Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 throug…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-19074

The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticat…

No fix yet
Fix from $4,000 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-46409

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des…

No fix yet
Fix from $2,300 2026-08-07