Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Rocket Font HIGH 8.8
CVE-2023-46067

Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Font plugin <= 1.2.3 versions.

Fix: after 1.2.3
Fix from $1,950 2023-10-21
Modoboa HIGH 8.8
CVE-2023-5690

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.

Fix: 2.2.2+
Fix from $1,950 2023-10-20
Mosparo HIGH 8.8
CVE-2023-5687

Cross-Site Request Forgery (CSRF) in GitHub repository mosparo/mosparo prior to 1.0.3.

Fix: 1.0.3+
Fix from $1,950 2023-10-20
Wpbot MEDIUM 5.4
CVE-2023-5534

The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to mis…

Fix: after 4.8.9
Fix from $1,600 2023-10-20
Social Media Share Buttons \& Social Sharing Icons HIGH 8.8
CVE-2023-5602

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc…

Fix: after 2.8.5
Fix from $1,950 2023-10-20
Imagemagick Engine HIGH 8.8
CVE-2022-2441

The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.…

Fix: after 1.7.5
Fix from $1,950 2023-10-20
Bear Woocommerce Bulk Editor And Products Manager Professional HIGH 8.8
CVE-2023-4920

The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect non…

Fix: after 1.1.3.3
Fix from $1,950 2023-10-20
Home Assistant Companion HIGH 8.8
CVE-2023-44385

The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious l…

Fix: 2023.7+
Fix from $1,950 2023-10-19
Ruckus Cloudpath Enrollment System CRITICAL 9.6
CVE-2023-45992

A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthentica…

Fix: after 5.12.5538
Fix from $2,300 2023-10-19
Dexgate HIGH 8.8
CVE-2023-42435

The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to perform actions with the permissions…

No fix yet
Fix from $1,950 2023-10-19
Open Journal System HIGH 8.8
CVE-2023-5626

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.

Fix: 3.3.0-16+
Fix from $1,950 2023-10-18
Dreamer Cms HIGH 8.8
CVE-2023-45901

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.

No fix yet
Fix from $1,950 2023-10-17
Dreamer Cms HIGH 8.8
CVE-2023-45902

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.

No fix yet
Fix from $1,950 2023-10-17
Dreamer Cms HIGH 8.8
CVE-2023-45903

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.

No fix yet
Fix from $1,950 2023-10-17
Dreamer Cms HIGH 8.8
CVE-2023-45904

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.

No fix yet
Fix from $1,950 2023-10-17
Dreamer Cms HIGH 8.8
CVE-2023-45905

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.

No fix yet
Fix from $1,950 2023-10-17
Dreamer Cms HIGH 8.8
CVE-2023-45906

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.

No fix yet
Fix from $1,950 2023-10-17
Dreamer Cms HIGH 8.8
CVE-2023-45907

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.

No fix yet
Fix from $1,950 2023-10-17
Fiber HIGH 8.8
CVE-2023-45128

Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w…

Fix: 2.50.0+
Fix from $1,950 2023-10-16
Fiber HIGH 8.8
CVE-2023-45141

Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, w…

Fix: 2.50.0+
Fix from $1,950 2023-10-16
Exos HIGH 8.8
CVE-2023-43118

Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 3…

Fix: 31.7.2 / 32.5.1.5+
Fix from $1,950 2023-10-16
Who Hit The Page Hit Counter HIGH 8.8
CVE-2023-46087

Cross-Site Request Forgery (CSRF) vulnerability in Mahlamusa Who Hit The Page – Hit Counter plugin <= 1.4.14.3 versions.

Fix: after 1.4.14.3
Fix from $1,950 2023-10-16
Which Template File HIGH 8.8
CVE-2023-45753

Cross-Site Request Forgery (CSRF) vulnerability in Gilles Dumas which template file plugin <= 4.6.0 versions.

Fix: after 4.6.0
Fix from $1,950 2023-10-16
Taggbox HIGH 8.8
CVE-2023-45763

Cross-Site Request Forgery (CSRF) vulnerability in Taggbox plugin <= 2.9 versions.

Fix: after 2.9
Fix from $1,950 2023-10-16
Google Amp HIGH 8.8
CVE-2023-45831

Cross-Site Request Forgery (CSRF) vulnerability in Pixelative, Mohsin Rafique AMP WP – Google AMP For WordPress plugin <= 1.5.15 versions.

Fix: after 1.5.15
Fix from $1,950 2023-10-16
Ultimate Taxonomy Manager HIGH 8.8
CVE-2023-45836

Cross-Site Request Forgery (CSRF) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions.

Fix: after 2.0
Fix from $1,950 2023-10-16
Mailchimp Forms HIGH 8.8
CVE-2023-45748

Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch plugin <= 3.1.4 versions.

Fix: after 3.1.4
Fix from $1,950 2023-10-16
Agp Font Awesome Collection HIGH 8.8
CVE-2023-45749

Cross-Site Request Forgery (CSRF) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions.

Fix: after 3.2.4
Fix from $1,950 2023-10-16
Post Gallery HIGH 8.8
CVE-2023-45752

Cross-Site Request Forgery (CSRF) vulnerability in 10 Quality Post Gallery plugin <= 2.3.12 versions.

Fix: after 2.3.12
Fix from $1,950 2023-10-16
Sort Searchresult By Title HIGH 8.8
CVE-2023-45639

Cross-Site Request Forgery (CSRF) vulnerability in Codex-m Sort SearchResult By Title plugin <= 10.0 versions.

Fix: after 10.0
Fix from $1,950 2023-10-16