Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Dedecms HIGH 8.8
CVE-2026-29839

DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.

Mitigation only
Fix from $1,950 2026-03-24
Mcp Go Sdk MEDIUM 6.5
CVE-2026-33252

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site…

Fix: 1.4.1+
Fix from $1,600 2026-03-24
Avideo HIGH 8.8
CVE-2026-33649

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts …

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.8
CVE-2026-33507

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users t…

Fix: after 26.0
Fix from $1,950 2026-03-23
Nebula300plus Firmware MEDIUM 6.5
CVE-2026-31849

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setS…

Fix: after 12.01.01.37
Fix from $1,600 2026-03-23
Unclassified MEDIUM 6.1
CVE-2026-2723

The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Mitigation only
Fix from $1,600 2026-03-21
Unclassified HIGH 8.1
CVE-2025-14037

The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2…

Mitigation only
Fix from $1,950 2026-03-21
Intranet Portal HIGH 8.8
CVE-2026-32989

Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafte…

No fix yet
Fix from $1,950 2026-03-20
Zimbra Collaboration Suite MEDIUM 5.4
CVE-2026-33372

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due t…

Fix: 10.1.16+
Fix from $1,600 2026-03-20
Unclassified HIGH 7.1
CVE-2024-32537

Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Pl…

Mitigation only
Fix from $1,950 2026-03-20
Admidio MEDIUM 5.7
CVE-2026-32755

Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php s…

Fix: 5.0.7+
Fix from $1,600 2026-03-19
Admidio MEDIUM 5.7
CVE-2026-32816

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-rol…

Fix: 5.0.7+
Fix from $1,600 2026-03-19
Mura Cms HIGH 8.8
CVE-2025-55040

The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack…

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms HIGH 8.0
CVE-2025-55041

MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allow…

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms MEDIUM 6.5
CVE-2025-55043

MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenti…

Mitigation only
Fix from $1,600 2026-03-18
Mura Cms HIGH 8.8
CVE-2025-55044

The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations …

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms HIGH 7.1
CVE-2025-55045

The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable…

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms HIGH 8.1
CVE-2025-55046

MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system thr…

Mitigation only
Fix from $1,950 2026-03-18
Unclassified HIGH 7.1
CVE-2026-22323

A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into send…

Mitigation only
Fix from $1,950 2026-03-18
Gs 5008pl Firmware MEDIUM 6.5
CVE-2026-32839

Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauth…

Fix: after 1.00.54
Fix from $1,600 2026-03-17
Streaming Engine HIGH 8.0
CVE-2016-20034

Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to adminis…

No fix yet
Fix from $1,950 2026-03-16
Realtyscript HIGH 8.8
CVE-2015-20117

Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthoriz…

No fix yet
Fix from $1,950 2026-03-16
Unclassified MEDIUM 6.5
CVE-2026-32443

Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forg…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.4
CVE-2026-32420

Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.This issue affects GamiPress: f…

Mitigation only
Fix from $1,600 2026-03-13
Unclassified MEDIUM 5.4
CVE-2026-32328

Cross-Site Request Forgery (CSRF) vulnerability in shufflehound Lemmony lemmony allows Cross Site Request Forgery.This issue affects Lemmony: from n/…

Mitigation only
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 5.4
CVE-2026-22215

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthor…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Wpdiscuz MEDIUM 6.5
CVE-2026-22202

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email addr…

Fix: 7.6.47+
Fix from $1,600 2026-03-13
Emlog HIGH 7.3
CVE-2026-31954

Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::check…

Fix: after 2.6.6
Fix from $1,950 2026-03-11
Opnsense HIGH 8.1
CVE-2026-30868

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but…

Fix: 26.1.4+
Fix from $1,950 2026-03-11
Unclassified HIGH 8.1
CVE-2026-2626

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated us…

Mitigation only
Fix from $1,950 2026-03-11