Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Paypal Payments HIGH 8.8
CVE-2023-35917

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions.

Fix: after 2.0.4
Fix from $1,950 2023-06-22
Form Builder HIGH 8.8
CVE-2023-23795

Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Form Builder plugin <= 1.9.9.0 versions.

Fix: after 1.9.9.0
Fix from $1,950 2023-06-22
Netman 204 Firmware HIGH 8.8
CVE-2022-3372

There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Fo…

Mitigation only
Fix from $1,950 2023-06-21
Hongcms HIGH 8.8
CVE-2020-21252

Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the up…

No fix yet
Fix from $1,950 2023-06-20
Greencms HIGH 8.0
CVE-2020-21366

Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.

No fix yet
Fix from $1,950 2023-06-20
Papercut Mf HIGH 8.8
CVE-2023-2533 KEVEPSS 29%

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in PaperCut NG/MF, which, under specific conditions, could potentially enable a…

Fix: 20.1.8 / 21.2.12+
Fix from $1,950 2023-06-20
Yzmcms MEDIUM 6.5
CVE-2020-20502

Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.

No fix yet
Fix from $1,600 2023-06-20
Gila Cms HIGH 8.8
CVE-2020-20726

Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user para…

No fix yet
Fix from $1,950 2023-06-20
Zephyr Project Manager HIGH 8.8
CVE-2023-34373

Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin <= 3.3.93 versions.

Fix: after 3.3.93
Fix from $1,950 2023-06-19
Printer Driver Packager Nx HIGH 7.8
CVE-2023-30759

The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected…

Fix: 1.1.26+
Fix from $1,950 2023-06-19
Google Xml Sitemap For Videos HIGH 8.8
CVE-2023-25055

Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.

Fix: after 2.6.1
Fix from $1,950 2023-06-15
Intrepidity HIGH 8.8
CVE-2023-27634

Cross-Site Request Forgery (CSRF) vulnerability allows arbitrary file upload in Shingo Intrepidity plugin <= 1.5.1 versions.

Fix: after 1.5.1
Fix from $1,950 2023-06-15
Ht Easy Ga4 \(google Analytics 4\) HIGH 8.8
CVE-2023-23802

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Easy GA4 ( Google Analytics 4 ) plugin <= 1.0.6 versions.

Fix: 1.0.7+
Fix from $1,950 2023-06-15
Givewp HIGH 8.8
CVE-2023-25450

Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform plugin <= 2.25.1 versions.

Fix: 2.25.2+
Fix from $1,950 2023-06-15
Cformsii HIGH 8.8
CVE-2023-25449

Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.

Fix: 15.0.5+
Fix from $1,950 2023-06-15
Dxp HIGH 8.8
CVE-2023-35030

Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP…

Fix: 7.4.3.77+
Fix from $1,950 2023-06-15
Digital.ai App Management Publisher MEDIUM 6.5
CVE-2023-35148

A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect t…

Fix: after 2.6
Fix from $1,600 2023-06-14
Jenkins HIGH 8.0
CVE-2023-35141

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includ…

Fix: 2.400 / 2.401.1+
Fix from $1,950 2023-06-14
Auto Upload Images MEDIUM 6.1
CVE-2022-42880

Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cross-Site Scripting (XSS).

Fix: 3.3.1+
Fix from $1,600 2023-06-13
Q200 Firmware HIGH 8.8
CVE-2023-30901

A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.11)…

Fix: 2.70+
Fix from $1,950 2023-06-13
Active Directory Integration \/ Ldap Integration MEDIUM 6.5
CVE-2023-2599

The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby…

Fix: after 4.1.4
Fix from $1,600 2023-06-09
Easy Google Maps MEDIUM 5.4
CVE-2023-2526

The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missin…

Fix: after 1.11.7
Fix from $1,600 2023-06-09
Announcement \& Notification Banner Bulletin MEDIUM 5.4
CVE-2023-2067

The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce validation …

Fix: after 3.7.0
Fix from $1,600 2023-06-09
Quiz And Survey Master HIGH 8.1
CVE-2023-0292

The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.0.8. This is due to m…

Fix: after 8.0.8
Fix from $1,950 2023-06-09
Vuforia Studio HIGH 8.0
CVE-2023-31200

PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a rep…

Fix: 9.9+
Fix from $1,950 2023-06-07
Process Steps Template Designer HIGH 8.8
CVE-2021-4349

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This ma…

Fix: after 1.2.1
Fix from $1,950 2023-06-07
Kali Forms HIGH 8.8
CVE-2020-36717

The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect non…

Fix: after 2.1.1
Fix from $1,950 2023-06-07
Nifty Coming Soon \& Maintenance Mode Page HIGH 8.8
CVE-2020-36707

The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This…

Fix: 1.58+
Fix from $1,950 2023-06-07
Favicon By Realfavicongenerator HIGH 8.8
CVE-2015-10116

A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function …

Fix: after 1.2.12
Fix from $1,950 2023-06-06
Minical MEDIUM 6.5
CVE-2023-33409

Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.

No fix yet
Fix from $1,600 2023-06-05