Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Shortcodes Ultimate HIGH 8.8
CVE-2022-41136

Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12…

Fix: after 5.12.0
Fix from $1,950 2022-11-08
Analytify Google Analytics Dashboard HIGH 8.8
CVE-2022-38137

Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.

Fix: 4.2.3+
Fix from $1,950 2022-11-08
Advanced Order Export For Woocommerce MEDIUM 6.5
CVE-2022-40128

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Order Export For WooCommerce plugin <= 3.3.2 on WordPress leading to export file download.

Fix: 3.3.3+
Fix from $1,600 2022-11-08
Simatic S7 1500 Software Controller MEDIUM 6.5
CVE-2022-30694

The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to t…

Fix: 3.2.19+
Fix from $1,600 2022-11-08
Role Based Pricing For Woocommerce HIGH 8.8
CVE-2022-3536

The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks, as well as does not validate…

Fix: 1.6.3+
Fix from $1,950 2022-11-07
Role Based Pricing For Woocommerce HIGH 8.8
CVE-2022-3537

The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files …

Fix: 1.6.2+
Fix from $1,950 2022-11-07
Wp Hide MEDIUM 5.3
CVE-2022-3489

The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom_wpadmin_slug settings, allow…

Fix: after 0.0.2
Fix from $1,600 2022-11-07
Domino HIGH 8.8
CVE-2022-38660

HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnera…

Fix: 9.0.1+
Fix from $1,950 2022-11-04
Identity Services Engine HIGH 8.8
CVE-2022-20961

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…

Fix: 2.6.0+
Fix from $1,950 2022-11-04
Simple Seo MEDIUM 5.4
CVE-2022-44627

Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers to create or delete sitemaps.

Fix: after 1.8.12
Fix from $1,600 2022-11-03
Simple Seo MEDIUM 5.4
CVE-2022-36404

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugin <= 1.8.12 versions.

Fix: after 1.8.12
Fix from $1,600 2022-11-03
Content Egg HIGH 8.8
CVE-2022-25952

Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress.

Fix: after 5.4.0
Fix from $1,950 2022-11-03
Infosphere Information Server HIGH 8.8
CVE-2022-30608

"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Patch available
Fix from $1,950 2022-11-03
Candidats HIGH 8.8
CVE-2022-42751

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from C…

No fix yet
Fix from $1,950 2022-11-03
Vr Calendar MEDIUM 6.5
CVE-2022-3852

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or i…

Fix: 2.3.4+
Fix from $1,600 2022-11-03
Restaurant Menu Food Ordering System Table Reservation HIGH 8.8
CVE-2022-3776

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an…

Fix: 2.3.2+
Fix from $1,950 2022-11-03
Php Point Of Sale HIGH 8.8
CVE-2022-40291

The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to …

Mitigation only
Fix from $1,950 2022-10-31
Automatic User Roles Switcher MEDIUM 6.5
CVE-2022-3419

The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users …

Fix: 1.1.2+
Fix from $1,600 2022-10-31
Processwire MEDIUM 6.5
CVE-2022-40488

ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).

Patch available
Fix from $1,600 2022-10-31
Dzzoffice HIGH 8.8
CVE-2022-43340

A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights t…

Mitigation only
Fix from $1,950 2022-10-27
Avada HIGH 8.8
CVE-2022-41996

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leading to arbitrary plugin install…

Fix: after 7.8.1
Fix from $1,950 2022-10-27
Adminpad MEDIUM 6.5
CVE-2022-2762

The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make a logged in admin update the…

Fix: 2.2+
Fix from $1,600 2022-10-25
Simple Exam Reviewer Management System HIGH 8.8
CVE-2022-42199

Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.

No fix yet
Fix from $1,950 2022-10-20
Pipeline\ HIGH 8.8
CVE-2022-43407

Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, wh…

Fix: after 451.vf1a_a_4f405289
Fix from $1,950 2022-10-19
Pipeline\ MEDIUM 6.5
CVE-2022-43408

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or a…

Fix: 2.27+
Fix from $1,600 2022-10-19
Eyoucms HIGH 8.8
CVE-2022-41500

EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and…

No fix yet
Fix from $1,950 2022-10-18
Zgr Tps200 Ng Firmware HIGH 8.8
CVE-2020-8976

The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with t…

Mitigation only
Fix from $1,950 2022-10-17
Nas1dual Firmware HIGH 8.8
CVE-2022-23771

This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lac…

Fix: 1.4.86+
Fix from $1,950 2022-10-17
Discord Integration MEDIUM 6.5
CVE-2022-3082

The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logge…

Fix: 2.1.6+
Fix from $1,600 2022-10-17
Wp Custom Cursors MEDIUM 6.1
CVE-2022-3149

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers …

Fix: 3.0.1+
Fix from $1,600 2022-10-17