Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Hotel Booking Engine \& Pms MEDIUM 6.5
CVE-2022-1407

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does n…

Fix: 1.5.8+
Fix from $1,600 2022-05-16
Social Stickers MEDIUM 6.1
CVE-2022-1418

The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network settings, and does not escape …

Fix: after 2.2.9
Fix from $1,600 2022-05-16
Bigfix Inventory MEDIUM 6.5
CVE-2021-27758

There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and s…

Fix: 10.0.7.0+
Fix from $1,600 2022-05-06
Bigfix Inventory MEDIUM 6.5
CVE-2021-27759

This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intent…

Fix: 10.0.7.0+
Fix from $1,600 2022-05-06
Gatemanager 4250 Firmware HIGH 8.8
CVE-2022-25778

Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get request in logged in user sess…

Fix: 9.7.622134021+
Fix from $1,950 2022-05-04
Options HIGH 8.8
CVE-2022-0916

An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF at…

Fix: 9.60.87+
Fix from $1,950 2022-05-03
Ad Invalid Click Protector MEDIUM 6.5
CVE-2022-0191

The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to ma…

Fix: 1.2.7+
Fix from $1,600 2022-05-02
Sitemap HIGH 8.8
CVE-2022-0952EPSS 11%

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does …

Fix: 1.0.36+
Fix from $1,950 2022-05-02
Auctionworx HIGH 8.0
CVE-2022-23904

Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to …

Fix: after 3.1
Fix from $1,950 2022-05-02
Subscribe To Comments Reloaded MEDIUM 5.4
CVE-2022-29414

Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows atta…

Fix: after 211130
Fix from $1,600 2022-04-29
Rara One Click Demo Import HIGH 8.8
CVE-2022-29451

Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows at…

Fix: 1.3.0+
Fix from $1,950 2022-04-29
Scada Server HIGH 8.8
CVE-2021-43937

Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intenti…

No fix yet
Fix from $1,950 2022-04-29
Mender HIGH 8.8
CVE-2022-29555

The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.

Fix: 3.2.2+
Fix from $1,950 2022-04-28
Hermit MEDIUM 5.4
CVE-2022-29412

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers to delete cache, delete …

Fix: after 3.1.6
Fix from $1,600 2022-04-28
Hermit MEDIUM 6.1
CVE-2022-29413

Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title …

Fix: after 3.1.6
Fix from $1,600 2022-04-28
Footer Text MEDIUM 6.1
CVE-2022-27860

Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.

Fix: after 2.0.3
Fix from $1,600 2022-04-28
Mahara HIGH 8.8
CVE-2022-28892

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too eas…

Fix: 20.10.5 / 21.04.4+
Fix from $1,950 2022-04-28
Shopware HIGH 7.5
CVE-2022-24879

Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) t…

Fix: 5.7.9+
Fix from $1,950 2022-04-28
Ax12 Firmware MEDIUM 6.5
CVE-2022-27374

Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at /goform/SysToolReboot.

No fix yet
Fix from $1,600 2022-04-25
Ax12 Firmware MEDIUM 6.5
CVE-2022-27375

Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at /goform/WifiExtraSet.

No fix yet
Fix from $1,600 2022-04-25
Thirstyaffiliates Affiliate Link Manager MEDIUM 5.4
CVE-2022-0398

The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links…

Fix: 3.10.5+
Fix from $1,600 2022-04-25
Mcms HIGH 8.8
CVE-2022-27340

MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges an…

No fix yet
Fix from $1,950 2022-04-22
Cognos Analytics HIGH 8.8
CVE-2021-38886

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and un…

Patch available
Fix from $1,950 2022-04-22
Gps Tracker HIGH 8.8
CVE-2021-32929

All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.

No fix yet
Fix from $1,950 2022-04-22
Unified Communications Manager MEDIUM 6.8
CVE-2022-20787

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Mana…

Fix: 12.5 / 14su1+
Fix from $1,600 2022-04-21
Micropayments HIGH 8.8
CVE-2022-27629

Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.…

Fix: 1.9.6+
Fix from $1,950 2022-04-20
Fancy Product Designer HIGH 8.8
CVE-2021-4096

The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for…

Fix: after 4.7.5
Fix from $1,950 2022-04-19
Selenium Grid HIGH 8.8
CVE-2022-28108EPSS 12%

Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data,…

Fix: 4.0.0+
Fix from $1,950 2022-04-19
Autolinks MEDIUM 5.4
CVE-2022-1112

The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape th…

Fix: after 1.0.1
Fix from $1,600 2022-04-18
Woo Product Table CRITICAL 9.8
CVE-2022-1020EPSS 26%

The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update…

Fix: 3.1.2+
Fix from $2,300 2022-04-18