Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jorani HIGH 8.8
CVE-2022-34134

Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.

Patch available
Fix from $1,950 2022-06-28
Html2wp HIGH 8.1
CVE-2022-1572

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such a…

Fix: after 1.0.0
Fix from $1,950 2022-06-27
Html2wp CRITICAL 9.8
CVE-2022-1574EPSS 12%

The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result,…

Fix: after 1.0.0
Fix from $2,300 2022-06-27
Mailpress MEDIUM 6.5
CVE-2022-1843

The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to make a logged in admin chang…

Fix: after 7.2.1
Fix from $1,600 2022-06-27
Minicms HIGH 8.1
CVE-2022-33121

A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.

No fix yet
Fix from $1,950 2022-06-24
Convertigo Mobile Platform HIGH 8.8
CVE-2022-34200

A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an atta…

Fix: after 1.1
Fix from $1,950 2022-06-23
Easyqa HIGH 8.8
CVE-2022-34203

A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP …

Fix: after 1.0
Fix from $1,950 2022-06-23
Jianliao Notification MEDIUM 6.5
CVE-2022-34205

A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests…

Fix: after 1.1
Fix from $1,600 2022-06-23
Beaker Builder MEDIUM 6.5
CVE-2022-34207

A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specif…

Fix: after 1.10
Fix from $1,600 2022-06-23
Threadfix MEDIUM 6.5
CVE-2022-34209

A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified …

Fix: after 1.5.4
Fix from $1,600 2022-06-23
Vrealize Orchestrator MEDIUM 6.5
CVE-2022-34211

A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST reque…

Fix: after 3.0
Fix from $1,600 2022-06-23
Global Content Blocks HIGH 8.8
CVE-2017-20090

A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The ma…

No fix yet
Fix from $1,950 2022-06-23
Library File Manager MEDIUM 6.5
CVE-2017-20091

A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown part. The manipulation leads t…

No fix yet
Fix from $1,600 2022-06-23
Pdf24 Articles To Pdf MEDIUM 6.5
CVE-2022-1828

The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to…

Fix: after 4.2.2
Fix from $1,600 2022-06-20
Inline Google Maps MEDIUM 6.5
CVE-2022-1829

The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which could allow attackers to mak…

Fix: after 5.11
Fix from $1,600 2022-06-20
Amazon Einzeltitellinks MEDIUM 6.5
CVE-2022-1830

The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings, which could allow attackers …

Fix: after 1.3.3
Fix from $1,600 2022-06-20
Wplite MEDIUM 6.5
CVE-2022-1831

The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Fix: after 1.3.1
Fix from $1,600 2022-06-20
Capa Protect MEDIUM 6.5
CVE-2022-1832

The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a…

Fix: after 0.5.8.2
Fix from $1,600 2022-06-20
Seamless Donations MEDIUM 6.5
CVE-2022-1610

The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which could allow attackers to mak…

Fix: 5.1.9+
Fix from $1,600 2022-06-20
Wp Email MEDIUM 6.5
CVE-2022-1630

The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in …

Fix: 2.69.0+
Fix from $1,600 2022-06-20
Multi Page Toolkit MEDIUM 5.4
CVE-2022-1818

The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which could allow attackers to make…

Fix: after 2.6
Fix from $1,600 2022-06-20
Cross Linker MEDIUM 6.5
CVE-2022-1826

The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which could allow attackers to make a …

Fix: after 3.0.1.9
Fix from $1,600 2022-06-20
Pdf24 Articles To Pdf MEDIUM 6.5
CVE-2022-1827

The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to …

Fix: after 4.2.2
Fix from $1,600 2022-06-20
Elefant Cms HIGH 8.8
CVE-2017-20062

A vulnerability was found in Elefant CMS 1.3.12-RC and classified as problematic. This issue affects some unknown processing. The manipulation leads …

No fix yet
Fix from $1,950 2022-06-20
Tew 831dr Firmware MEDIUM 6.5
CVE-2022-30327

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacker can change the pre-shared k…

No fix yet
Fix from $1,600 2022-06-16
Tew 831dr Firmware MEDIUM 6.5
CVE-2022-30328

An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interface does not require entering …

Mitigation only
Fix from $1,600 2022-06-16
Jforum HIGH 8.8
CVE-2022-26173

JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attack…

Mitigation only
Fix from $1,950 2022-06-16
Online Discussion Forum Site MEDIUM 6.5
CVE-2022-31294

An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user account…

No fix yet
Fix from $1,600 2022-06-16
Admin Management Xtended HIGH 8.8
CVE-2022-29450

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress.

Fix: after 2.4.4
Fix from $1,950 2022-06-15
Image Slider By Nextcode HIGH 8.8
CVE-2022-29437

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress.

Fix: after 1.1.2
Fix from $1,950 2022-06-15