Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Malinky Ajax Pagination HIGH 8.8
CVE-2023-34033

Cross-Site Request Forgery (CSRF) vulnerability in Malinky Ajax Pagination and Infinite Scroll plugin <= 2.0.1 versions.

Fix: after 2.0.1
Fix from $1,950 2023-11-09
Ts Webfonts For Sakura HIGH 8.8
CVE-2023-34169

Cross-Site Request Forgery (CSRF) vulnerability in SAKURA Internet Inc. TS Webfonts for さくらのレンタルサーバ plugin <= 3.1.2 versions.

Fix: 3.1.3+
Fix from $1,950 2023-11-09
Wp Report Post HIGH 8.8
CVE-2023-34171

Cross-Site Request Forgery (CSRF) vulnerability in Alex Raven WP Report Post plugin <= 2.1.2 versions.

Fix: after 2.1.2
Fix from $1,950 2023-11-09
Wp Cachecom HIGH 8.8
CVE-2023-34177

Cross-Site Request Forgery (CSRF) vulnerability in Kenth Hagström WP-Cache.Com plugin <= 1.1.1 versions.

Fix: after 1.1.1
Fix from $1,950 2023-11-09
Groundhogg HIGH 8.8
CVE-2023-34178

Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg plugin <= 2.7.11 versions.

Fix: 2.7.11.1+
Fix from $1,950 2023-11-09
Wp Cirrus HIGH 8.8
CVE-2023-34181

Cross-Site Request Forgery (CSRF) vulnerability in WP-Cirrus plugin <= 0.6.11 versions.

Fix: after 0.6.11
Fix from $1,950 2023-11-09
Lh Password Changer HIGH 8.8
CVE-2023-34182

Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions.

Fix: after 1.55
Fix from $1,950 2023-11-09
Spamreferrerblock HIGH 8.8
CVE-2023-34371

Cross-Site Request Forgery (CSRF) vulnerability in Didier Sampaolo SpamReferrerBlock plugin <= 2.22 versions.

Fix: after 2.22
Fix from $1,950 2023-11-09
Auto Publish For Google My Business HIGH 8.8
CVE-2023-47237

Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson Auto Publish for Google My Business plugin <= 3.7 versions.

Fix: 3.8+
Fix from $1,950 2023-11-09
Top 10 HIGH 8.8
CVE-2023-47238

Cross-Site Request Forgery (CSRF) vulnerability in WebberZone Top 10 – WordPress Popular posts by WebberZone plugin <= 3.3.2 versions.

Fix: 3.3.3+
Fix from $1,950 2023-11-09
Etsy Shop HIGH 8.8
CVE-2023-25975

Cross-Site Request Forgery (CSRF) vulnerability in Frédéric Sheedy Etsy Shop plugin <= 3.0.3 versions.

Fix: 3.0.4+
Fix from $1,950 2023-11-09
Js Job Manager HIGH 8.8
CVE-2023-31087

Cross-Site Request Forgery (CSRF) vulnerability in JoomSky JS Job Manager plugin <= 2.0.0 versions.

Fix: 2.0.1+
Fix from $1,950 2023-11-09
Wp Inventory Manager HIGH 8.8
CVE-2023-34002

Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions.

Fix: 2.1.0.14+
Fix from $1,950 2023-11-09
Wpc Smart Wishlist For Woocommerce HIGH 8.8
CVE-2023-34386

Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions.

Fix: 4.7.2+
Fix from $1,950 2023-11-09
Wp Helper Premium HIGH 8.8
CVE-2023-46614

Cross-Site Request Forgery (CSRF) vulnerability in Mat Bao Corp WP Helper Premium plugin <= 4.5.1 versions.

Fix: 4.5.2+
Fix from $1,950 2023-11-09
Openmct MEDIUM 6.5
CVE-2023-45884

Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the f…

Fix: after 3.1.0
Fix from $1,600 2023-11-09
Publish To Schedule HIGH 8.8
CVE-2023-25994

Cross-Site Request Forgery (CSRF) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.4.2 versions.

Fix: 4.5.4+
Fix from $1,950 2023-11-09
Axios MEDIUM 6.5
CVE-2023-45857

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKE…

No fix yet
Fix from $1,600 2023-11-08
Updraftplus MEDIUM 5.4
CVE-2023-5982

The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl…

Fix: after 1.23.10
Fix from $1,600 2023-11-07
Xwiki HIGH 8.8
CVE-2023-46242

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execut…

Fix: 14.10.7 / 15.2+
Fix from $1,950 2023-11-07
Email Templates Customizer And Designer HIGH 8.8
CVE-2022-47181

Cross-Site Request Forgery (CSRF) vulnerability in wpexpertsio Email Templates Customizer and Designer for WordPress and WooCommerce email-templates …

Fix: after 1.4.2
Fix from $1,950 2023-11-07
Jazz Popups MEDIUM 6.1
CVE-2023-32966

Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popups: from n/a through 1.8.7.

Fix: after 1.8.7
Fix from $1,600 2023-11-07
Auto Excerpt Everywhere HIGH 8.8
CVE-2023-46776

Cross-Site Request Forgery (CSRF) vulnerability in Serena Villa Auto Excerpt everywhere plugin <= 1.5 versions.

Fix: after 1.5
Fix from $1,950 2023-11-06
Custom Login Page \| Temporary Users \| Rebrand Login \| Login Captcha HIGH 8.8
CVE-2023-46777

Cross-Site Request Forgery (CSRF) vulnerability in Custom Login Page | Temporary Users | Rebrand Login | Login Captcha plugin <= 1.1.3 versions.

Fix: after 1.1.3
Fix from $1,950 2023-11-06
Auto Limit Posts Reloaded HIGH 8.8
CVE-2023-46778

Cross-Site Request Forgery (CSRF) vulnerability in TheFreeWindows Auto Limit Posts Reloaded plugin <= 2.5 versions.

Fix: after 2.5
Fix from $1,950 2023-11-06
Easyrecipe HIGH 8.8
CVE-2023-46779

Cross-Site Request Forgery (CSRF) vulnerability in EasyRecipe plugin <= 3.5.3251 versions.

Fix: after 3.5.3251
Fix from $1,950 2023-11-06
Alter HIGH 8.8
CVE-2023-46780

Cross-Site Request Forgery (CSRF) vulnerability in Alter plugin <= 1.0 versions.

Fix: after 1.0
Fix from $1,950 2023-11-06
Current Menu Item For Custom Post Types HIGH 8.8
CVE-2023-46781

Cross-Site Request Forgery (CSRF) vulnerability in Roland Murg Current Menu Item for Custom Post Types plugin <= 1.5 versions.

Fix: after 1.5
Fix from $1,950 2023-11-06
Kadence Woocommerce Email Designer HIGH 8.8
CVE-2023-47186

Cross-Site Request Forgery (CSRF) vulnerability in Kadence WP Kadence WooCommerce Email Designer plugin <= 1.5.11 versions.

Fix: after 1.5.11
Fix from $1,950 2023-11-06
Tk Google Fonts Gdpr Compliant HIGH 8.8
CVE-2023-5823

Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions.

Fix: after 2.2.11
Fix from $1,950 2023-11-06