Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Mass Delete Unused Tags HIGH 8.8
CVE-2023-27430

Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Mass Delete Unused Tags plugin <= 2.0.0 versions.

Fix: 3.0.0+
Fix from $1,950 2023-05-18
Contact Form HIGH 8.8
CVE-2023-2528

The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due …

Fix: after 1.7.24
Fix from $1,950 2023-05-17
Appspider HIGH 8.8
CVE-2023-32998

A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified…

Fix: after 1.0.15
Fix from $1,950 2023-05-16
Wso2 Oauth MEDIUM 5.4
CVE-2023-33006

A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the…

Fix: after 1.0
Fix from $1,600 2023-05-16
Saml Single Sign On HIGH 8.8
CVE-2023-32991

A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP reque…

Fix: after 2.0.2
Fix from $1,950 2023-05-16
Saml Single Sign On HIGH 8.8
CVE-2023-32995

A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST …

Fix: after 2.0.0
Fix from $1,950 2023-05-16
Reverse Proxy Auth HIGH 8.8
CVE-2023-32987

A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-s…

Fix: after 1.7.4
Fix from $1,950 2023-05-16
Azure Vm Agents HIGH 8.8
CVE-2023-32989

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an …

Fix: after 852.v8d35f0960a_43
Fix from $1,950 2023-05-16
Unifi Os MEDIUM 6.5
CVE-2023-28361

A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential info…

Fix: 3.0.13+
Fix from $1,600 2023-05-11
Factorytalk Vantagepoint HIGH 8.8
CVE-2023-2444

A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways.…

Fix: 8.40+
Fix from $1,950 2023-05-11
Interactive Svg Image Map Builder HIGH 8.8
CVE-2022-45846

Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro for WordPress - Interactive SVG Image Map Builder plugin < 5.6.9 versions.

Fix: 5.6.9+
Fix from $1,950 2023-05-10
Liquid Speech Balloon HIGH 8.8
CVE-2023-27889

Cross-site request forgery (CSRF) vulnerability in LIQUID SPEECH BALLOON versions prior to 1.2 allows a remote unauthenticated attacker to hijack the…

Fix: 1.2+
Fix from $1,950 2023-05-10
Portal For Arcgis HIGH 8.8
CVE-2023-25832

There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authoriz…

Fix: after 11.0
Fix from $1,950 2023-05-09
Verydows HIGH 8.8
CVE-2020-23363

Cross Site Request Forgery (CSRF) vulnerability found in Verytops Verydows all versions that allows an attacker to execute arbitrary code via a craft…

No fix yet
Fix from $1,950 2023-05-09
Enable\/disable Auto Login When Register MEDIUM 6.5
CVE-2023-0522

The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could …

Fix: after 1.1.0
Fix from $1,600 2023-05-08
Clanscripts HIGH 8.8
CVE-2020-18131

Cross Site Request Forgery (CSRF) vulnerability in Bluethrust Clan Scripts v4 allows attackers to escilate privledges to an arbitrary account via a c…

No fix yet
Fix from $1,950 2023-05-08
Beescms MEDIUM 6.5
CVE-2020-22334

Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /admin/admi…

No fix yet
Fix from $1,600 2023-05-08
Flycms HIGH 8.8
CVE-2020-36065

Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts via system/admin/admin_save.

No fix yet
Fix from $1,950 2023-05-08
Bumsys HIGH 8.8
CVE-2023-2552

Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.

Fix: 2.1.1+
Fix from $1,950 2023-05-05
GitLab MEDIUM 6.5
CVE-2023-1965

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, a…

Fix: 15.9.6 / 15.10.5+
Fix from $1,600 2023-05-03
Peepso HIGH 8.8
CVE-2023-25967

Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo plugin <= 6.0.2.0 versions.

Fix: 6.0.3.0+
Fix from $1,950 2023-05-03
Pods HIGH 8.8
CVE-2023-23790

Cross-Site Request Forgery (CSRF) vulnerability in Pods Framework Team Pods – Custom Content Types and Fields plugin <= 2.9.10.2 versions.

Fix: 2.9.11+
Fix from $1,950 2023-05-03
Category Specific Rss Feed Subscription HIGH 8.8
CVE-2023-22691

Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.1 versions.

Fix: 2.2+
Fix from $1,950 2023-05-03
Mccms HIGH 8.8
CVE-2023-29815

mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).

No fix yet
Fix from $1,950 2023-04-28
Qwik MEDIUM 6.5
CVE-2023-2307

Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.

Fix: 0.104.0+
Fix from $1,600 2023-04-26
Pingfederate HIGH 8.8
CVE-2022-40724

The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF) through crafted GET request…

Fix: after 11.2.2
Fix from $1,950 2023-04-25
Churchcrm MEDIUM 6.5
CVE-2023-26841

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is curr…

No fix yet
Fix from $1,600 2023-04-25
Churchcrm MEDIUM 5.3
CVE-2023-26840

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administr…

No fix yet
Fix from $1,600 2023-04-25
Repetier Server HIGH 8.8
CVE-2023-31061

Repetier Server through 1.4.10 does not have CSRF protection.

Fix: after 1.4.10
Fix from $1,950 2023-04-24
Activity Reactions For Buddypress HIGH 8.8
CVE-2022-45074

Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <= 1.0.22 ve…

Fix: after 1.0.22
Fix from $1,950 2023-04-23