Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Op Xt71000n Firmware MEDIUM 6.5
CVE-2020-23593

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to cond…

Mitigation only
Fix from $1,600 2022-11-23
Fastify HIGH 8.8
CVE-2022-41919

Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight…

Fix: 3.29.4 / 4.10.2+
Fix from $1,950 2022-11-22
All In One Wp Security \& Firewall HIGH 8.8
CVE-2022-44737

Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress.

Fix: after 5.1.0
Fix from $1,950 2022-11-22
Op Xt71000n Firmware MEDIUM 6.5
CVE-2020-23582

A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a c…

Mitigation only
Fix from $1,600 2022-11-21
Creative Mail HIGH 8.8
CVE-2022-44740

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Creative Mail plugin <= 1.5.4 on WordPress.

Fix: after 1.5.4
Fix from $1,950 2022-11-18
Wordpress Rest Api Authentication HIGH 8.8
CVE-2022-45073

Cross-Site Request Forgery (CSRF) vulnerability in REST API Authentication plugin <= 2.4.0 on WordPress.

Fix: after 2.4.0
Fix from $1,950 2022-11-18
Integration For Szamlazz.hu \& Woocommerce HIGH 8.8
CVE-2022-41685

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Viszt Péter's Integration for Szamlazz.hu & WooCommerce plugin <= 5.6.3.2 and Csomagpon…

Fix: 1.9.0.3 / 5.6.3.3+
Fix from $1,950 2022-11-18
Store Locator MEDIUM 6.1
CVE-2022-41615

Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress.

Fix: 1.4.6+
Fix from $1,600 2022-11-18
Media Library Folders HIGH 8.8
CVE-2022-41634

Cross-Site Request Forgery (CSRF) vulnerability in Media Library Folders plugin <= 7.1.1 on WordPress.

Fix: 7.1.2+
Fix from $1,950 2022-11-18
Seo Redirection HIGH 8.8
CVE-2022-40695

Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.

Fix: 9.1+
Fix from $1,950 2022-11-18
Mantenimiento Web MEDIUM 6.1
CVE-2022-38075

Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Mantenimiento web plugin <= 0.13 on WordPress.

Fix: 0.14+
Fix from $1,600 2022-11-18
Creative Mail HIGH 8.8
CVE-2022-40686

Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

Fix: 1.6.0+
Fix from $1,950 2022-11-18
Creative Mail HIGH 8.8
CVE-2022-40687

Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.

Fix: 1.6.0+
Fix from $1,950 2022-11-18
Wpforo Forum HIGH 8.8
CVE-2022-40192

Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

Fix: after 2.0.9
Fix from $1,950 2022-11-17
Wpml HIGH 8.8
CVE-2022-45071

Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.

Fix: 4.5.14+
Fix from $1,950 2022-11-17
Duofox Cms HIGH 8.8
CVE-2022-42246

Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.

No fix yet
Fix from $1,950 2022-11-17
Hospital Management Center HIGH 8.8
CVE-2022-4013

A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the …

No fix yet
Fix from $1,950 2022-11-16
Follow Me Plugin HIGH 8.8
CVE-2022-3240

The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missi…

Fix: after 3.1.1
Fix from $1,950 2022-11-15
Konker Platform HIGH 8.8
CVE-2022-35613

Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF).

Mitigation only
Fix from $1,950 2022-11-15
Eyoucms HIGH 8.8
CVE-2022-44387

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member modul…

Mitigation only
Fix from $1,950 2022-11-14
Eyoucms MEDIUM 6.5
CVE-2022-44389

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows at…

Mitigation only
Fix from $1,600 2022-11-14
Eyoucms HIGH 8.8
CVE-2022-43323

EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.

No fix yet
Fix from $1,950 2022-11-14
Concrete Cms HIGH 8.8
CVE-2022-43693

Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use th…

Fix: 8.5.10+
Fix from $1,950 2022-11-14
Oauth Client MEDIUM 6.5
CVE-2022-3632

The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logge…

Fix: after 1.1.0
Fix from $1,600 2022-11-14
Webmaster Tools Verification MEDIUM 6.5
CVE-2022-3538

The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling plugins, allowing unauthenti…

Fix: after 1.2
Fix from $1,600 2022-11-14
Resmush.it Image Optimizer MEDIUM 6.5
CVE-2022-2449

The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actio…

Fix: 0.4.7+
Fix from $1,600 2022-11-14
Obsidian MEDIUM 6.5
CVE-2022-45130

Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsidian is a specific version of…

No fix yet
Fix from $1,600 2022-11-10
Dedecms HIGH 8.8
CVE-2022-43031

DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add Administrator accounts and mod…

No fix yet
Fix from $1,950 2022-11-09
Testimonial Slider HIGH 8.8
CVE-2022-44741

Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPre…

Fix: after 1.3.1
Fix from $1,950 2022-11-08
Wpforo Forum MEDIUM 5.4
CVE-2022-40632

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.

Fix: after 2.0.5
Fix from $1,600 2022-11-08