Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 6.1
CVE-2026-2324

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Mitigation only
Fix from $1,600 2026-03-11
Getsimple Cms HIGH 8.8
CVE-2026-28495

GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administr…

Fix: after 3.3.22
Fix from $1,950 2026-03-10
Instantcms HIGH 7.1
CVE-2026-28281

InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers gra…

Fix: 2.18.1+
Fix from $1,950 2026-03-10
Sunbirded Portal HIGH 8.8
CVE-2025-70031

An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Mitigation only
Fix from $1,950 2026-03-09
Computer Laboratory Management System HIGH 8.8
CVE-2026-3770

A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site …

No fix yet
Fix from $1,950 2026-03-08
Ghost HIGH 8.8
CVE-2026-29784

Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to …

Fix: 6.19.3+
Fix from $1,950 2026-03-07
Php Oop Cms Blog HIGH 8.8
CVE-2018-25200

OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by …

No fix yet
Fix from $1,950 2026-03-06
Easyndexer MEDIUM 6.5
CVE-2018-25190

Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative accounts by submitt…

No fix yet
Fix from $1,600 2026-03-06
Unclassified MEDIUM 5.3
CVE-2018-25174

ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credentials by submitting forged requ…

No fix yet
Fix from $1,600 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25176

Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici…

No fix yet
Fix from $1,950 2026-03-06
Unclassified MEDIUM 5.3
CVE-2018-25177

Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator passwords without authentica…

No fix yet
Fix from $1,600 2026-03-06
Unclassified HIGH 8.2
CVE-2018-25170

DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thro…

No fix yet
Fix from $1,950 2026-03-06
Unclassified MEDIUM 5.1
CVE-2026-1468

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the vict…

Mitigation only
Fix from $1,600 2026-03-06
Unclassified HIGH 7.5
CVE-2026-3589

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to ma…

Mitigation only
Fix from $1,950 2026-03-06
Chamilo Lms HIGH 8.1
CVE-2025-59541

Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete pro…

Fix: 1.11.34+
Fix from $1,950 2026-03-06
Openclaw HIGH 7.1
CVE-2026-28477

OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to …

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Rustdesk CRITICAL 9.8
CVE-2026-30793

Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter UR…

Fix: after 1.4.5
Fix from $2,300 2026-03-05
Mercurius MEDIUM 5.4
CVE-2025-64166

Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue aris…

Fix: 16.4.0+
Fix from $1,600 2026-03-05
Concrete Cms MEDIUM 6.8
CVE-2026-2994

Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter…

Fix: 9.4.8+
Fix from $1,600 2026-03-04
Impact Mobile HIGH 8.1
CVE-2021-35486

A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwri…

Fix: after 19.11.2.10-20210118042150283
Fix from $1,950 2026-03-03
Sl902 Swtgw124as Firmware MEDIUM 6.5
CVE-2026-27758

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows…

Fix: after 200.1.20
Fix from $1,600 2026-02-27
Parse Dashboard MEDIUM 6.5
CVE-2026-27609

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint…

Mitigation only
Fix from $1,600 2026-02-25
Caddy MEDIUM 6.5
CVE-2026-27589

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`)…

Fix: 2.11.1+
Fix from $1,600 2026-02-24
Traccar HIGH 8.7
CVE-2026-25649

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 …

Fix: after 6.11.1
Fix from $1,950 2026-02-23
Unclassified MEDIUM 5.1
CVE-2026-23694

Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affectin…

Mitigation only
Fix from $1,600 2026-02-23
Web Site Management Server MEDIUM 6.5
CVE-2025-13671

Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could ma…

No fix yet
Fix from $1,600 2026-02-19
Openclaw HIGH 7.1
CVE-2026-26317

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without expl…

Fix: 2026.2.14+
Fix from $1,950 2026-02-19
Unclassified MEDIUM 5.4
CVE-2026-27050

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress RealPress realpress allows Cross Site Request Forgery.This issue affects RealPress: from…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.4
CVE-2026-25422

Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request Forgery.This issue affects Pop…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.4
CVE-2026-25337

Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n…

Mitigation only
Fix from $1,600 2026-02-19