Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Wordpress Exit Box Lite HIGH 8.8
CVE-2013-10029

A vulnerability classified as problematic was found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this vulnerability is the function e…

Fix: after 1.06
Fix from $1,950 2023-06-05
Blogger Importer HIGH 8.8
CVE-2013-10027

A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/re…

Fix: 0.6+
Fix from $1,950 2023-06-04
Contact Form Builder By Vcita MEDIUM 6.1
CVE-2023-2301

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10.3. This is …

Fix: after 4.9.1
Fix from $1,600 2023-06-03
Contact Form And Calls To Action By Vcita MEDIUM 6.1
CVE-2023-2303

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.10…

Fix: after 2.6.4
Fix from $1,600 2023-06-03
Crm And Lead Management By Vcita MEDIUM 6.5
CVE-2023-2405

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.0. This i…

Fix: after 2.6.2
Fix from $1,600 2023-06-03
Event Registration Calendar By Vcita MEDIUM 6.5
CVE-2023-2407

The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plu…

Fix: after 3.9.1
Fix from $1,600 2023-06-03
Online Booking \& Scheduling Calendar MEDIUM 6.5
CVE-2023-2416

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing non…

Fix: after 4.2.10
Fix from $1,600 2023-06-03
Page Builder With Image Map By Azexo HIGH 8.8
CVE-2023-3052

The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to…

Fix: after 1.27.133
Fix from $1,950 2023-06-03
Corebos MEDIUM 6.5
CVE-2023-3075

Cross-Site Request Forgery (CSRF) in GitHub repository tsolucio/corebos prior to 8.

Fix: 8.0+
Fix from $1,600 2023-06-02
Video And Media Plug In HIGH 8.8
CVE-2015-10109

A vulnerability was found in Video Playlist and Gallery Plugin up to 1.136 on WordPress. It has been rated as problematic. Affected by this issue is …

Fix: 1.137+
Fix from $1,950 2023-06-01
Pythagorean Oa Office System HIGH 8.8
CVE-2023-3029

A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. This vulnerability affects unkn…

Fix: after 4.50.31
Fix from $1,950 2023-06-01
Inline Google Spreadsheet Viewer HIGH 8.8
CVE-2015-10108

A vulnerability was found in meitar Inline Google Spreadsheet Viewer Plugin up to 0.9.6 on WordPress and classified as problematic. Affected by this …

Fix: after 0.9.6
Fix from $1,950 2023-05-31
Feather Login Page HIGH 8.8
CVE-2023-2549

The Feather Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions starting from 1.0.7 up to, and including, 1.1.1. …

Fix: after 1.1.1
Fix from $1,950 2023-05-31
Twitter HIGH 8.8
CVE-2012-10015

A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twtt…

Fix: 2.15+
Fix from $1,950 2023-05-31
Shop Beat Media Player HIGH 8.8
CVE-2022-36250

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Cross Site Request Forgery (CSRF).

Fix: 3.2.57+
Fix from $1,950 2023-05-30
Custom Twitter Feeds HIGH 8.8
CVE-2022-33974

Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.

Fix: after 1.8.4
Fix from $1,950 2023-05-29
Product Gallery Slider For Woocommerce HIGH 8.8
CVE-2022-45372

Cross-Site Request Forgery (CSRF) vulnerability in Codeixer Product Gallery Slider for WooCommerce plugin <= 2.2.8 versions.

Fix: after 2.2.8
Fix from $1,950 2023-05-29
Download Plugin HIGH 8.8
CVE-2022-36345

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Plugin <= 2.0.4 versions.

Fix: 2.0.5+
Fix from $1,950 2023-05-28
Easy Google Maps HIGH 8.8
CVE-2023-33926

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <= 1.11.7 versions.

Fix: 1.11.8+
Fix from $1,950 2023-05-28
Wip Custom Login HIGH 8.8
CVE-2023-33313

Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions.

Fix: 1.3.0+
Fix from $1,950 2023-05-28
Automatewoo HIGH 8.8
CVE-2023-33316

Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Follow-Up Emails (AutomateWoo) plugin <= 4.9.40 versions.

Fix: 4.9.50+
Fix from $1,950 2023-05-28
Jetformbuilder HIGH 8.8
CVE-2023-33212

Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.

Fix: 3.0.7+
Fix from $1,950 2023-05-28
Bear Woocommerce Bulk Editor And Products Manager Professional HIGH 8.8
CVE-2023-33314

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.

Fix: 1.1.3.2+
Fix from $1,950 2023-05-28
Smart App Banner HIGH 8.8
CVE-2023-33315

Cross-Site Request Forgery (CSRF) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <= 1.1.2 versions.

Fix: 1.1.3+
Fix from $1,950 2023-05-28
Youtube Playlist Player HIGH 8.8
CVE-2023-33931

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.4 versions.

Fix: 4.6.5+
Fix from $1,950 2023-05-28
Better Notifications For Wp HIGH 8.8
CVE-2023-32964

Cross-Site Request Forgery (CSRF) vulnerability in Made with Fuel Better Notifications for WP plugin <= 1.9.2 versions.

Fix: 1.9.3+
Fix from $1,950 2023-05-26
Schema HIGH 8.8
CVE-2023-25058

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Schema – All In One Schema Rich Snippets plugin <= 1.6.5 versions.

Fix: 1.6.6+
Fix from $1,950 2023-05-26
Resize At Upload Plus HIGH 8.8
CVE-2023-25467

Cross-Site Request Forgery (CSRF) vulnerability in Daniel Mores, A. Huizinga Resize at Upload Plus plugin <= 1.3 versions.

Fix: after 1.3
Fix from $1,950 2023-05-26
Wp Clean Up HIGH 8.8
CVE-2023-25034

Cross-Site Request Forgery (CSRF) vulnerability in BoLiQuan WP Clean Up plugin <= 1.2.3 versions.

Fix: after 1.2.3
Fix from $1,950 2023-05-26
Wp Social Bookmarking Light HIGH 8.8
CVE-2023-25029

Cross-Site Request Forgery (CSRF) vulnerability in utahta WP Social Bookmarking Light plugin <= 2.0.7 versions.

Fix: after 2.0.7
Fix from $1,950 2023-05-26