Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Employee Leaves Management System MEDIUM 6.5
CVE-2022-30931

Employee Leaves Management System (ELMS) V 2.1 is vulnerable to Cross Site Request Forgery (CSRF) via /myprofile.php.

No fix yet
Fix from $1,600 2022-06-14
Wpmk Ajax Finder HIGH 8.8
CVE-2022-1749

The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the…

Fix: after 1.0.1
Fix from $1,950 2022-06-13
Mobile Browser Color Select HIGH 8.8
CVE-2022-1969

The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due…

Fix: after 1.0.1
Fix from $1,950 2022-06-13
Quick Subscribe MEDIUM 5.4
CVE-2022-1792

The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Fix: after 1.7.1
Fix from $1,600 2022-06-13
Copify HIGH 8.8
CVE-2022-1900

The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce val…

Fix: after 1.3.0
Fix from $1,950 2022-06-13
Toolbar To Share HIGH 8.8
CVE-2022-1918

The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing n…

Fix: after 2.0
Fix from $1,950 2022-06-13
Genki Pre Publish Reminder HIGH 8.8
CVE-2022-1758

The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attacke…

Fix: after 1.4.1
Fix from $1,950 2022-06-13
Rb Internal Links MEDIUM 5.4
CVE-2022-1759

The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to ma…

Fix: after 2.0.16
Fix from $1,600 2022-06-13
Peter\'s Collaboration E Mails MEDIUM 6.5
CVE-2022-1761

The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This allows the change of its set…

Fix: after 2.2.0
Fix from $1,600 2022-06-13
Static Page Extended MEDIUM 5.4
CVE-2022-1763

Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, …

Fix: after 2.1
Fix from $1,600 2022-06-13
Wp Chgfontsize MEDIUM 5.4
CVE-2022-1764

The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a l…

Fix: after 1.8
Fix from $1,600 2022-06-13
Hot Linked Image Cacher HIGH 8.8
CVE-2022-1765

The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on th…

Fix: after 1.16
Fix from $1,950 2022-06-13
Auto Delete Posts HIGH 8.1
CVE-2022-1779

The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to mak…

Fix: after 1.3.0
Fix from $1,950 2022-06-13
Latex MEDIUM 5.4
CVE-2022-1780

The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could allow attackers to make a log…

Fix: after 3.4.10
Fix from $1,600 2022-06-13
Posttabs MEDIUM 5.4
CVE-2022-1781

The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logg…

Fix: after 2.10.6
Fix from $1,600 2022-06-13
Sideblog MEDIUM 5.4
CVE-2022-1787

The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Fix: after 6.0
Fix from $1,600 2022-06-13
Change Uploaded File Permissions MEDIUM 6.5
CVE-2022-1788

Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change t…

Fix: after 4.0.0
Fix from $1,600 2022-06-13
New User Email Set Up MEDIUM 6.5
CVE-2022-1790

The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to…

Fix: after 0.5.2
Fix from $1,600 2022-06-13
One Click Plugin Updater HIGH 8.1
CVE-2022-1791

The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attacker…

Fix: after 2.4.14
Fix from $1,950 2022-06-13
Email Users MEDIUM 6.5
CVE-2022-1605

The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a lo…

Fix: after 4.8.8
Fix from $1,600 2022-06-13
Social Locker MEDIUM 6.5
CVE-2022-1608

The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers t…

Fix: after 5.6.2
Fix from $1,600 2022-06-13
Webriti Smtp Mail MEDIUM 6.5
CVE-2022-1612

The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Fix: after 1.0
Fix from $1,600 2022-06-13
Latest Tweets Widget MEDIUM 6.5
CVE-2022-1624

The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, which could allow attackers to …

Fix: after 1.1.4
Fix from $1,600 2022-06-13
Useful Banner Manager MEDIUM 6.5
CVE-2022-1694

The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to tri…

Fix: after 1.6.1
Fix from $1,600 2022-06-13
Enqueue Anything MEDIUM 6.5
CVE-2021-25116

The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure …

Fix: after 1.0.1
Fix from $1,600 2022-06-13
Pricepoint HIGH 8.8
CVE-2017-20045

A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation …

No fix yet
Fix from $1,950 2022-06-13
Spectrum Copy Data Management HIGH 8.8
CVE-2022-22479

IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malici…

Fix: after 2.2.15.0
Fix from $1,950 2022-06-10
Fuel Cms HIGH 8.8
CVE-2021-44117

A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

No fix yet
Fix from $1,950 2022-06-10
Solar Log 250 Firmware HIGH 8.8
CVE-2017-20020

A vulnerability, which was classified as problematic, has been found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this issue is some unknown fu…

No fix yet
Fix from $1,950 2022-06-09
Cscms MEDIUM 6.5
CVE-2022-30898

A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username an…

No fix yet
Fix from $1,600 2022-06-09