Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Wzone MEDIUM 6.5
CVE-2022-27628

Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions.

Mitigation only
Fix from $1,600 2023-02-06
Xxl Job MEDIUM 6.5
CVE-2023-0674

A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the fi…

No fix yet
Fix from $1,600 2023-02-04
Fuel Cms HIGH 8.8
CVE-2021-36569

Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.

Patch available
Fix from $1,950 2023-02-03
Fuel Cms HIGH 8.8
CVE-2021-36570

Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.

Patch available
Fix from $1,950 2023-02-03
Modern Honey Network MEDIUM 6.5
CVE-2021-37234

Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensit…

Fix: 2021-10-30+
Fix from $1,600 2023-02-03
Imcat HIGH 8.8
CVE-2021-36443

Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification.

No fix yet
Fix from $1,950 2023-02-03
Imcat HIGH 8.8
CVE-2021-36444

Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation…

No fix yet
Fix from $1,950 2023-02-03
Academy Lms HIGH 8.8
CVE-2022-47132

A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.

Fix: 5.10+
Fix from $1,950 2023-02-03
Js Help Desk HIGH 8.8
CVE-2022-46842

Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.

Fix: 2.7.2+
Fix from $1,950 2023-02-02
Conditional Shipping For Woocommerce HIGH 8.8
CVE-2022-46815

Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 versions.

Fix: 2.3.2+
Fix from $1,950 2023-02-02
Exclusive Addons For Elementor HIGH 8.8
CVE-2022-45067

Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions.

Fix: 2.6.2+
Fix from $1,950 2023-02-02
Wp Mail Log HIGH 8.8
CVE-2022-45807

Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions.

Fix: 1.0.2+
Fix from $1,950 2023-02-02
Sunshine Photo Cart HIGH 8.8
CVE-2022-40692

Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions.

Fix: 2.9.14+
Fix from $1,950 2023-02-02
Homepage Pop Up HIGH 8.8
CVE-2022-44585

Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.

Fix: after 1.2.5
Fix from $1,950 2023-02-02
Terawallet HIGH 8.8
CVE-2022-36401

Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions.

Fix: 1.4.0+
Fix from $1,950 2023-02-02
Squidex MEDIUM 6.5
CVE-2023-0642

Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.

Fix: 7.4.0+
Fix from $1,600 2023-02-02
Clockwork Web MEDIUM 6.5
CVE-2023-25015

Clockwork Web before 0.1.2, when Rails before 5.2 is used, allows CSRF.

Fix: 0.1.2+
Fix from $1,600 2023-02-02
Joomla\! MEDIUM 6.3
CVE-2023-23750

An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messag…

Fix: after 4.2.6
Fix from $1,600 2023-02-01
Vrealize Operations HIGH 8.8
CVE-2023-20856

VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of th…

Fix: after 8.6.4
Fix from $1,950 2023-02-01
Conext Combox Firmware MEDIUM 6.5
CVE-2022-32516

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the …

Mitigation only
Fix from $1,600 2023-01-30
Fl3r Feelbox MEDIUM 6.1
CVE-2022-4552

The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, w…

Fix: after 8.1
Fix from $1,600 2023-01-30
Pandora Fms MEDIUM 5.4
CVE-2022-43980

There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An attacker could modify a networ…

Fix: 766+
Fix from $1,600 2023-01-27
Quick Restaurant Menu HIGH 8.1
CVE-2023-0554

The Quick Restaurant Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This is due to mi…

Fix: 2.1.0+
Fix from $1,950 2023-01-27
Keycloak Authentication MEDIUM 6.5
CVE-2023-24457

A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into lo…

Fix: after 2.3.0
Fix from $1,600 2023-01-26
Bearychat HIGH 8.8
CVE-2023-24458

A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified …

Fix: after 3.0.2
Fix from $1,950 2023-01-26
Openid HIGH 8.8
CVE-2023-24446

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the att…

Fix: after 2.4
Fix from $1,950 2023-01-26
Rabbitmq Consumer HIGH 8.8
CVE-2023-24447

A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-spec…

Fix: after 2.8
Fix from $1,950 2023-01-26
Testquality Updater HIGH 8.8
CVE-2023-24452

A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers to connect to an attacker-sp…

Fix: after 1.3
Fix from $1,950 2023-01-26
Bitbucket Oauth MEDIUM 5.7
CVE-2023-24428

A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in …

Fix: 0.13+
Fix from $1,600 2023-01-26
Orka By Macstadium HIGH 8.8
CVE-2023-24432

A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers to connect to an attacker-sp…

Fix: 1.32+
Fix from $1,950 2023-01-26