Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Accept Stripe Donation Aidwp HIGH 8.8
CVE-2022-47422

Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin Accept Stripe Donation – AidWP plugin <= 3.1.5 versions.

Fix: after 3.1.5
Fix from $1,950 2023-03-14
Multi Rating HIGH 8.8
CVE-2022-47443

Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.5 versions.

Fix: after 5.0.5
Fix from $1,950 2023-03-14
Wp Dynamic Keywords Injector HIGH 8.8
CVE-2022-47141

Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions.

Fix: after 2.3.15
Fix from $1,950 2023-03-14
Css Js Manager\, Async Javascript\, Defer Render Blocking Css Supports Woocommerce HIGH 8.8
CVE-2022-47154

Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce pl…

Fix: after 2.4.49
Fix from $1,950 2023-03-14
Slider HIGH 8.8
CVE-2022-47155

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Slider by Supsystic plugin <= 1.8.5 versions.

Fix: after 1.8.5
Fix from $1,950 2023-03-14
Dh Anti Adblocker HIGH 8.8
CVE-2022-47162

Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions.

Fix: after 36
Fix from $1,950 2023-03-14
Wp Csv To Database HIGH 7.5
CVE-2022-47163

Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= …

Fix: after 2.6
Fix from $1,950 2023-03-14
Prestashop HIGH 8.8
CVE-2023-25170

PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authen…

Fix: 8.0.1+
Fix from $1,950 2023-03-13
Auto Affiliate Links HIGH 8.8
CVE-2023-25973

Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions.

Fix: 6.3.0.3+
Fix from $1,950 2023-03-13
Registrationmagic HIGH 8.8
CVE-2023-25991

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.

Fix: 5.1.9.3+
Fix from $1,950 2023-03-13
Void Contact Form 7 Widget For Elementor Page Builder HIGH 8.8
CVE-2022-47166

Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.

Fix: 2.2+
Fix from $1,950 2023-03-13
My Tickets HIGH 8.8
CVE-2022-47440

Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Tickets plugin <= 1.9.10 versions.

Fix: 1.9.11+
Fix from $1,950 2023-03-13
Rax30 Firmware HIGH 8.8
CVE-2023-1205

NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented…

Fix: 1.0.10.94+
Fix from $1,950 2023-03-10
Next Auth HIGH 8.8
CVE-2023-27490

NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.…

Fix: 4.20.1+
Fix from $1,950 2023-03-09
Wp Statistics MEDIUM 6.5
CVE-2021-4333

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing o…

Fix: after 13.1.1
Fix from $1,600 2023-03-07
Jetbackup HIGH 8.8
CVE-2020-36669

The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.3.9.…

Fix: after 1.3.9
Fix from $1,950 2023-03-07
Replyable HIGH 8.8
CVE-2022-4265

The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiating an object in the prompt_dis…

Fix: 2.2.10+
Fix from $1,950 2023-03-06
Woolentor Woocommerce Elementor Addons \+ Builder MEDIUM 5.4
CVE-2022-46798

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.

Fix: 2.5.2+
Fix from $1,600 2023-03-01
Conditional Shipping For Woocommerce MEDIUM 5.4
CVE-2022-46805

Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activatio…

Fix: 2.3.2+
Fix from $1,600 2023-03-01
Mercado Pago Payments For Woocommerce HIGH 8.8
CVE-2022-45068

Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1.

Fix: 6.4.0+
Fix from $1,950 2023-03-01
Robo Gallery MEDIUM 5.4
CVE-2022-45804

Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries h…

Fix: 3.2.11+
Fix from $1,600 2023-03-01
Contact Us Page Contact People MEDIUM 6.5
CVE-2023-23973

Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0.

Fix: 3.7.1+
Fix from $1,600 2023-03-01
Quick Event Manager MEDIUM 5.4
CVE-2023-23974

Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete a…

Fix: 9.7.5+
Fix from $1,600 2023-03-01
Bubble Menu MEDIUM 5.4
CVE-2023-23984

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leading to form deletion.

Fix: 3.0.2+
Fix from $1,600 2023-03-01
Opencats MEDIUM 5.4
CVE-2023-27295

Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating…

No fix yet
Fix from $1,600 2023-02-28
Responsive Vertical Icon Menu MEDIUM 5.4
CVE-2023-23983

Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to theme deletion.

Fix: 1.5.9+
Fix from $1,600 2023-02-28
Captainform HIGH 8.8
CVE-2022-43459

Cross-Site Request Forgery (CSRF) vulnerability in Forms by CaptainForm – Form Builder for WordPress plugin <= 2.5.3 versions.

Fix: after 2.5.3
Fix from $1,950 2023-02-28
Formidable Form Builder HIGH 8.8
CVE-2023-24419

Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions.

Fix: 5.5.7+
Fix from $1,950 2023-02-28
Froxlor HIGH 8.8
CVE-2023-1033

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.

Fix: 2.0.11+
Fix from $1,950 2023-02-25
Taocms HIGH 8.8
CVE-2021-34167

Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php.

No fix yet
Fix from $1,950 2023-02-24