Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Openclaw HIGH 7.1
CVE-2026-41347

OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site reques…

Fix: 2026.3.31+
Fix from $1,950 2026-04-23
Unclassified CRITICAL 9.6
CVE-2026-40471

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage s…

Mitigation only
Fix from $2,300 2026-04-23
GitLab HIGH 8.1
CVE-2026-4922

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that co…

Fix: 18.9.6 / 18.10.4+
Fix from $1,950 2026-04-22
Unclassified MEDIUM 6.1
CVE-2026-4131

The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified MEDIUM 6.1
CVE-2026-4090

The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing…

Mitigation only
Fix from $1,600 2026-04-22
Avideo HIGH 7.1
CVE-2026-40926

WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objec…

Fix: after 29.0
Fix from $1,950 2026-04-21
Avideo MEDIUM 5.4
CVE-2026-40928

WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/` accept state-changing reque…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.4
CVE-2026-40929

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mutating JSON endpoint that del…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo HIGH 8.3
CVE-2026-40925

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) pe…

Fix: after 29.0
Fix from $1,950 2026-04-21
Goshs HIGH 8.1
CVE-2026-40883

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing…

No fix yet
Fix from $1,950 2026-04-21
Unclassified MEDIUM 5.4
CVE-2026-41194

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /m…

Patch available
Fix from $1,600 2026-04-21
Ad Self Update MEDIUM 6.3
CVE-2026-31014

Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing reque…

Fix: 4.0.0.5+
Fix from $1,600 2026-04-21
Firefox MEDIUM 5.3
CVE-2026-6777

Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox MEDIUM 6.5
CVE-2026-6755

Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Apache Airflow Providers Keycloak MEDIUM 5.4
CVE-2026-40948

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login …

Fix: 0.7.0+
Fix from $1,600 2026-04-18
Unclassified HIGH 8.1
CVE-2026-40581

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs per…

Patch available
Fix from $1,950 2026-04-18
Pac4j MEDIUM 6.5
CVE-2026-40458

PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, …

Fix: 5.7.10 / 6.4.1+
Fix from $1,600 2026-04-17
Unclassified MEDIUM 6.1
CVE-2026-1852

The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. T…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified HIGH 8.1
CVE-2026-40764

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affe…

Mitigation only
Fix from $1,950 2026-04-15
Mattermost Server HIGH 8.1
CVE-2026-28741

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpo…

Fix: 10.11.13 / 11.3.3+
Fix from $1,950 2026-04-15
Unclassified MEDIUM 6.1
CVE-2026-4091

The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.0. This is due to missing n…

Mitigation only
Fix from $1,600 2026-04-15
Resourcespace HIGH 7.1
CVE-2019-25693

ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious…

No fix yet
Fix from $1,950 2026-04-12
Metagpt HIGH 8.8
CVE-2026-6109

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environ…

Fix: after 0.8.1
Fix from $1,950 2026-04-12
Dockyard MEDIUM 5.4
CVE-2026-39848

Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without …

Fix: 1.1.0+
Fix from $1,600 2026-04-09
Phpbb HIGH 8.8
CVE-2025-70810

Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the aut…

No fix yet
Fix from $1,950 2026-04-09
Zammad MEDIUM 6.5
CVE-2026-34721

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and…

Fix: 6.5.4+
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-0811

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is …

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-1672

The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request For…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-39710

Cross-Site Request Forgery (CSRF) vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Cross Site Request Forgery.This issue affec…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified HIGH 7.1
CVE-2026-39671

Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout allows Cross …

Mitigation only
Fix from $1,950 2026-04-08