Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
User Role HIGH 8.8
CVE-2023-0820

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrar…

Fix: 1.6.7+
Fix from $1,950 2023-04-03
Octoperf Load Testing HIGH 8.8
CVE-2023-28674

A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a p…

Fix: after 4.5.2
Fix from $1,950 2023-04-02
Convert To Pipeline HIGH 8.8
CVE-2023-28676

A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based o…

Fix: after 1.0
Fix from $1,950 2023-04-02
Hcl Compass HIGH 8.8
CVE-2022-42447

HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate…

Fix: 2.2.1+
Fix from $1,950 2023-04-02
Gmace HIGH 8.8
CVE-2023-23861

Cross-Site Request Forgery (CSRF) vulnerability in German Mesky GMAce plugin <= 1.5.2 versions.

Fix: after 1.5.2
Fix from $1,950 2023-03-29
Popup Anything HIGH 8.8
CVE-2022-38077

Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversi…

Fix: after 2.2.1
Fix from $1,950 2023-03-29
Gmace HIGH 8.8
CVE-2023-1509

The GMAce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing nonce vali…

Fix: after 1.5.2
Fix from $1,950 2023-03-29
Osprey Pump Controller Firmware HIGH 8.0
CVE-2023-28718

Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. T…

Mitigation only
Fix from $1,950 2023-03-28
Wp Shamsi MEDIUM 6.5
CVE-2023-0335

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delet…

Fix: after 4.3.3
Fix from $1,600 2023-03-27
Ooohboi Steroids For Elementor MEDIUM 6.5
CVE-2023-0336

The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low…

Fix: 2.1.5+
Fix from $1,600 2023-03-27
Wordpress Ping Optimizer HIGH 8.8
CVE-2022-30705

Cross-Site Request Forgery (CSRF) vulnerability in Pankaj Jha WordPress Ping Optimizer plugin <= 2.35.1.2.3 versions.

Fix: 2.35.1.3.0+
Fix from $1,950 2023-03-27
Moodle HIGH 8.8
CVE-2023-28335

The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

Patch available
Fix from $1,950 2023-03-23
Sd Wan HIGH 8.1
CVE-2023-20113

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a c…

Fix: 20.6.5+
Fix from $1,950 2023-03-23
Horizon MEDIUM 6.7
CVE-2023-0870

A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacke…

Fix: 31.0.6 / 2020.1.33+
Fix from $1,600 2023-03-22
Superior Faq HIGH 8.8
CVE-2023-22678

Cross-Site Request Forgery (CSRF) vulnerability in Rafael Dery Superior FAQ plugin <= 1.0.2 versions.

Fix: after 1.0.2
Fix from $1,950 2023-03-20
Admin Log HIGH 8.8
CVE-2023-23721

Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions.

Fix: after 1.50
Fix from $1,950 2023-03-20
Eexamhall Project MEDIUM 6.5
CVE-2023-22681

Cross-Site Request Forgery (CSRF) vulnerability in Aarvanshinfotech Online Exam Software: eExamhall plugin <= 4.0 versions.

Fix: after 4.0
Fix from $1,600 2023-03-20
Launchpad Coming Soon \& Maintenance Mode Plugin HIGH 8.8
CVE-2022-46854

Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions.

Fix: after 1.0.13
Fix from $1,950 2023-03-17
Universal Star Rating HIGH 8.8
CVE-2022-46867

Cross-Site Request Forgery (CSRF) vulnerability in Chasil Universal Star Rating plugin <= 2.1.0 version.

Fix: after 2.1.0
Fix from $1,950 2023-03-17
Rapidload Power Up For Autoptimize MEDIUM 6.3
CVE-2023-1472

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.1. This…

Fix: 1.7.2+
Fix from $1,600 2023-03-17
Social Login Wp HIGH 8.8
CVE-2022-38063

Cross-Site Request Forgery (CSRF) vulnerability in Social Login WP plugin <= 5.0.0.0 versions.

Fix: after 5.0.0.0
Fix from $1,950 2023-03-16
My Calendar HIGH 8.8
CVE-2022-47427

Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.

Fix: after 3.3.24.1
Fix from $1,950 2023-03-15
Wp Vr HIGH 8.8
CVE-2023-25708

Cross-Site Request Forgery (CSRF) vulnerability in Rextheme WP VR – 360 Panorama and Virtual Tour Builder For WordPress plugin <= 8.2.7 versions.

Fix: 8.2.8+
Fix from $1,950 2023-03-15
Locatoraid HIGH 8.8
CVE-2023-25709

Cross-Site Request Forgery (CSRF) vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.11 versions.

Fix: after 3.9.11
Fix from $1,950 2023-03-15
Client Portal HIGH 8.8
CVE-2023-25968

Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin…

Fix: 1.1.9+
Fix from $1,950 2023-03-15
Jizhicms MEDIUM 6.5
CVE-2023-27234

A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration changes within the appli…

No fix yet
Fix from $1,600 2023-03-15
Dynamics 365 MEDIUM 5.4
CVE-2023-24920

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Fix: 9.0.45.11 / 9.1.16.20+
Fix from $1,600 2023-03-14
Online Food Ordering System MEDIUM 6.5
CVE-2023-27073

A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST re…

Mitigation only
Fix from $1,600 2023-03-14
Multiple Page Generator HIGH 8.8
CVE-2022-47143

Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions.

Fix: after 3.3.9
Fix from $1,950 2023-03-14
Ipblocklist HIGH 8.8
CVE-2022-47147

Cross-Site Request Forgery (CSRF) vulnerability in Kesz1 Technologies ipBlockList plugin <= 1.0 versions.

Fix: after 1.0
Fix from $1,950 2023-03-14