Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Add Multiple Marker HIGH 8.8
CVE-2022-45080

Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions.

Fix: after 1.2
Fix from $1,950 2023-04-23
Nice Paypal Button Lite HIGH 8.8
CVE-2023-22686

Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions.

Fix: after 1.3.5
Fix from $1,950 2023-04-23
Php Execution HIGH 8.8
CVE-2023-23879

Cross-Site Request Forgery (CSRF) vulnerability in Nicolas Zeh PHP Execution plugin <= 1.0.0 versions.

Fix: after 1.0.0
Fix from $1,950 2023-04-23
Kodexplorer HIGH 8.8
CVE-2022-4944

A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown func…

Fix: after 4.49
Fix from $1,950 2023-04-22
Passport MEDIUM 6.5
CVE-2023-29020

@fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by…

Fix: 1.1.0 / 2.3.0+
Fix from $1,600 2023-04-21
Modoboa MEDIUM 6.8
CVE-2023-2228

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.

Fix: 2.1.0+
Fix from $1,600 2023-04-21
Csrf Protection MEDIUM 6.5
CVE-2023-27495

@fastify/csrf-protection is a plugin which helps protect Fastify servers against CSRF attacks. The CSRF protection enforced by the @fastify/csrf-prot…

Fix: 4.1.0 / 6.3.0+
Fix from $1,600 2023-04-20
Form Block MEDIUM 6.5
CVE-2023-30616

Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a …

Fix: 1.0.2+
Fix from $1,600 2023-04-20
Xwiki HIGH 8.8
CVE-2023-29213

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-04-17
Ultimate Noindex Nofollow Tool Ii HIGH 8.8
CVE-2023-30474

Cross-Site Request Forgery (CSRF) vulnerability in Kilian Evang Ultimate Noindex Nofollow Tool II plugin <= 1.3 versions.

Fix: after 1.3
Fix from $1,950 2023-04-16
GitLab HIGH 8.8
CVE-2018-17451

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site…

Fix: 11.1.7 / 11.2.4+
Fix from $1,950 2023-04-15
Report Portal HIGH 8.8
CVE-2023-30525

A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specifie…

Fix: after 0.5
Fix from $1,950 2023-04-12
Doyocms HIGH 8.8
CVE-2020-19803

Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the background system s…

Mitigation only
Fix from $1,950 2023-04-11
Lp 9200ps2 Firmware MEDIUM 6.5
CVE-2023-27520

Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hija…

Mitigation only
Fix from $1,600 2023-04-11
Facebook Button HIGH 8.8
CVE-2012-10012

A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the fu…

Fix: after 2.13
Fix from $1,950 2023-04-10
Contact Form HIGH 8.8
CVE-2012-10010

A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page o…

Patch available
Fix from $1,950 2023-04-09
Exit Strategy HIGH 8.8
CVE-2013-10025

A vulnerability was found in Exit Strategy Plugin 1.55 on WordPress and classified as problematic. Affected by this issue is the function exitpageadm…

Patch available
Fix from $1,950 2023-04-08
Sveltekit HIGH 8.8
CVE-2023-29008

The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint han…

Fix: 1.15.2+
Fix from $1,950 2023-04-06
Product Feed Pro For Woocommerce HIGH 8.8
CVE-2022-46793

Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions.

Fix: 12.4.5+
Fix from $1,950 2023-04-06
Really Simple Google Tag Manager HIGH 8.8
CVE-2023-23801

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Really Simple Google Tag Manager plugin <= 1.0.6 versions.

Fix: 1.0.7+
Fix from $1,950 2023-04-06
Wcfm Membership HIGH 8.8
CVE-2022-4941

The WCFM Membership plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10 due to missing nonce ch…

Fix: 2.10.0+
Fix from $1,950 2023-04-05
Wcfm Marketplace HIGH 8.8
CVE-2022-4936

The WCFM Marketplace plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.11 due to missing nonce c…

Fix: 3.4.12+
Fix from $1,950 2023-04-05
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible HIGH 8.8
CVE-2022-4938

The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing non…

Fix: after 6.5.13
Fix from $1,950 2023-04-05
Prime Infrastructure MEDIUM 6.5
CVE-2023-20130

Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) co…

Fix: 3.10.2 / 5.0.2.5+
Fix from $1,600 2023-04-05
Vitalpbx HIGH 8.8
CVE-2023-0480

VitalPBX version 3.2.3-8 allows an unauthenticated external attacker to obtain the instance administrator's account. This is possible because the app…

No fix yet
Fix from $1,950 2023-04-04
Sveltekit HIGH 8.8
CVE-2023-29003

SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a …

Fix: 1.15.1+
Fix from $1,950 2023-04-04
Mm Wiki HIGH 8.8
CVE-2020-19278

Cross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via the system/user/save…

No fix yet
Fix from $1,950 2023-04-04
User Oidc MEDIUM 5.4
CVE-2023-28848

user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effect…

Fix: 1.3.0+
Fix from $1,600 2023-04-04
Peepso HIGH 8.8
CVE-2022-41633

Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin <= 6.0…

Fix: 6.0.3.0+
Fix from $1,950 2023-04-04
Redirection MEDIUM 6.5
CVE-2023-1330

The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add r…

Fix: 1.1.4+
Fix from $1,600 2023-04-03