Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Custom Field Template HIGH 8.8
CVE-2023-22695

Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions.

Fix: 2.5.9+
Fix from $1,950 2023-07-10
Redirect Manager HIGH 8.8
CVE-2023-23787

Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions.

Fix: after 1.0.9
Fix from $1,950 2023-07-10
Ht Feed HIGH 8.8
CVE-2023-23804

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions.

Fix: 1.2.8+
Fix from $1,950 2023-07-10
Google Xml Sitemap For Mobile HIGH 8.8
CVE-2023-23869

Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions.

Fix: after 1.6.1
Fix from $1,950 2023-07-10
Simple Mobile Url Redirect HIGH 8.8
CVE-2023-23897

Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.

Fix: after 1.7.2
Fix from $1,950 2023-07-10
Ip Blocker Lite HIGH 8.8
CVE-2023-23993

Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions.

Fix: after 11.1.1
Fix from $1,950 2023-07-10
Contact Form 7 Redirect \& Thank You Page HIGH 8.8
CVE-2023-24395

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions.

Fix: 1.0.4+
Fix from $1,950 2023-07-10
Paypal \& Stripe Add On HIGH 8.8
CVE-2023-24405

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions.

Fix: 1.9.4+
Fix from $1,950 2023-07-10
Weather Station HIGH 8.8
CVE-2023-25478

Cross-Site Request Forgery (CSRF) vulnerability in Jason Rouet Weather Station plugin <= 3.8.12 versions.

Fix: after 3.8.12
Fix from $1,950 2023-07-10
Online Examination System MEDIUM 6.5
CVE-2023-36256

The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link …

No fix yet
Fix from $1,600 2023-07-07
Conduit Ap Mtcap2 L4e1 868 042a Firmware HIGH 8.8
CVE-2023-25201

Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows a remote attacker to execute …

No fix yet
Fix from $1,950 2023-07-07
M Bus 900s Firmware HIGH 8.8
CVE-2023-35120

PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send a phishing mail to the owner …

Mitigation only
Fix from $1,950 2023-07-07
Yzncms MEDIUM 6.5
CVE-2023-37131

A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Ad…

No fix yet
Fix from $1,600 2023-07-06
Icinga Web Jira Integration HIGH 8.8
CVE-2023-30607

icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configurati…

Fix: 1.3.2+
Fix from $1,950 2023-07-05
Oauth2 HIGH 8.8
CVE-2023-31999

All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users. The purp…

Fix: 7.2.0+
Fix from $1,950 2023-07-04
Zzcms HIGH 8.8
CVE-2023-36162

Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.ph…

No fix yet
Fix from $1,950 2023-07-03
Style Kits HIGH 8.8
CVE-2021-4401

The Style Kits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.0. This is due to missing or in…

Fix: after 1.8.0
Fix from $1,950 2023-07-01
Abandoned Cart Recovery For Woocommerce MEDIUM 6.5
CVE-2021-4395

The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.4.…

Fix: after 1.0.4
Fix from $1,600 2023-07-01
Bridge HIGH 8.8
CVE-2021-4399

The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or…

Fix: after 2.0.6
Fix from $1,950 2023-07-01
Wp Project Manager HIGH 8.8
CVE-2020-36745

The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missi…

Fix: after 2.4.0
Fix from $1,950 2023-07-01
Radio Buttons For Taxonomies HIGH 8.8
CVE-2020-36740

The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is du…

Fix: after 2.0.5
Fix from $1,950 2023-07-01
Opal Estate HIGH 8.8
CVE-2021-4387

The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or …

Fix: after 1.6.11
Fix from $1,950 2023-07-01
Catfishcms MEDIUM 6.8
CVE-2020-18409

Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions vi…

No fix yet
Fix from $1,600 2023-06-27
Jymusic MEDIUM 6.8
CVE-2020-18416

An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/ad…

No fix yet
Fix from $1,600 2023-06-27
Feifeicms HIGH 8.8
CVE-2020-18418

A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts vi…

No fix yet
Fix from $1,950 2023-06-27
Pbx MEDIUM 6.8
CVE-2023-34839

A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF expl…

No fix yet
Fix from $1,600 2023-06-27
Yoga Class Registration System HIGH 8.8
CVE-2023-1722

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does n…

No fix yet
Fix from $1,950 2023-06-24
Wolf Wordpress Posts Bulk Editor And Manager Professional HIGH 8.8
CVE-2023-34028

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions.

Fix: after 1.0.7
Fix from $1,950 2023-06-22
Updraftplus MEDIUM 6.1
CVE-2023-32960

Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sit…

Fix: after 1.23.3
Fix from $1,600 2023-06-22
Casdoor MEDIUM 6.5
CVE-2023-34927

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows…

Fix: after 1.331.0
Fix from $1,600 2023-06-22