Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 5.4
CVE-2026-39634

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request Forgery.This issue affects Gra…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-39635

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified CRITICAL 9.6
CVE-2026-39640

Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39641

Cross-Site Request Forgery (CSRF) vulnerability in Skywarrior Blackfyre blackfyre allows Cross Site Request Forgery.This issue affects Blackfyre: fro…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39632

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.This issue affects Grand Blog: f…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified MEDIUM 6.5
CVE-2026-39633

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Car Rental grandcarrental allows Cross Site Request Forgery.This issue affects Gr…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified CRITICAL 9.6
CVE-2026-39620

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affec…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified HIGH 8.8
CVE-2026-39621

Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects Spi…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified CRITICAL 9.6
CVE-2026-39617

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestr…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.6
CVE-2026-39619

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Bus…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-39603

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects…

Mitigation only
Fix from $1,600 2026-04-08
Unclassified HIGH 8.8
CVE-2026-3499

The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in …

Mitigation only
Fix from $1,950 2026-04-08
Unclassified MEDIUM 5.4
CVE-2026-4401

The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods…

Mitigation only
Fix from $1,600 2026-04-08
Redwoodsdk HIGH 8.1
CVE-2026-39371

RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET …

Fix: 1.0.6+
Fix from $1,950 2026-04-07
Unclassified HIGH 7.5
CVE-2026-34896

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.Thi…

Mitigation only
Fix from $1,950 2026-04-07
Unclassified HIGH 7.5
CVE-2026-34904

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects S…

Mitigation only
Fix from $1,950 2026-04-07
Redaxo MEDIUM 6.5
CVE-2016-20053

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tr…

No fix yet
Fix from $1,600 2026-04-04
Emlog MEDIUM 6.5
CVE-2026-34228

Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parame…

Fix: 2.6.8+
Fix from $1,600 2026-04-03
Datapower Gateway HIGH 8.8
CVE-2025-36375

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 1…

Fix: 10.5.0.21 / 10.6.0.9+
Fix from $1,950 2026-04-01
Payload MEDIUM 5.4
CVE-2026-34749

Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exis…

Fix: 3.79.1+
Fix from $1,600 2026-04-01
Chrome MEDIUM 6.5
CVE-2026-5283

Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML…

Fix: 146.0.7680.177+
Fix from $1,600 2026-04-01
Avideo MEDIUM 6.5
CVE-2026-34611

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to…

Fix: after 26.0
Fix from $1,600 2026-03-31
Avideo MEDIUM 6.5
CVE-2026-34613

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to …

Fix: after 26.0
Fix from $1,600 2026-03-31
Admidio HIGH 7.3
CVE-2026-34384

Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/r…

Fix: 5.0.8+
Fix from $1,950 2026-03-31
Avideo HIGH 8.1
CVE-2026-34394

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks an…

Fix: after 26.0
Fix from $1,950 2026-03-31
Unclassified MEDIUM 5.4
CVE-2026-3191

The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing…

Mitigation only
Fix from $1,600 2026-03-31
Zimbra Collaboration Suite HIGH 8.8
CVE-2026-33373

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client du…

Fix: 10.0.18 / 10.1.13+
Fix from $1,950 2026-03-30
Fireware MEDIUM 6.5
CVE-2026-4315

A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (D…

Fix: 11.12.4 / 12.5.18+
Fix from $1,600 2026-03-30
Botpress HIGH 8.2
CVE-2026-4984

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it…

Mitigation only
Fix from $1,950 2026-03-27
GitLab HIGH 8.8
CVE-2026-3857

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that cou…

Fix: 18.8.7 / 18.9.3+
Fix from $1,950 2026-03-25