Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Phpipam MEDIUM 6.1
CVE-2021-46426

phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.

Patch available
Fix from $1,600 2022-03-25
Passwork HIGH 8.8
CVE-2022-25268

Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.

Fix: 4.6.13+
Fix from $1,950 2022-03-23
Yoo Slider MEDIUM 5.4
CVE-2022-25608

Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into u…

Fix: after 2.0.0
Fix from $1,600 2022-03-23
Xiaohuanxiong Cms MEDIUM 6.5
CVE-2021-43737

An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.

No fix yet
Fix from $1,600 2022-03-23
Xiaohuanxiong Cms HIGH 8.8
CVE-2021-43738

An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.

No fix yet
Fix from $1,950 2022-03-23
Chamilo HIGH 8.8
CVE-2021-40662

A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a…

Patch available
Fix from $1,950 2022-03-21
Bigant Server HIGH 8.8
CVE-2022-23349

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

Mitigation only
Fix from $1,950 2022-03-21
Simple Membership MEDIUM 6.5
CVE-2022-0681

The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which could allow attackers to make…

Fix: 4.1.0+
Fix from $1,600 2022-03-21
Google Authenticator HIGH 8.1
CVE-2022-0229

The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMet…

Fix: 5.5+
Fix from $1,950 2022-03-21
Advanced Cf7 Db HIGH 8.0
CVE-2021-24905

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX act…

Fix: 1.8.7+
Fix from $1,950 2022-03-21
Aria HIGH 8.8
CVE-2022-24235

A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code v…

No fix yet
Fix from $1,950 2022-03-21
Ru21 Firmware HIGH 8.8
CVE-2022-27226EPSS 31%

A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration pa…

Fix: after 2022-03-16
Fix from $1,950 2022-03-19
Extended Choice Parameter HIGH 8.8
CVE-2022-27204

A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to …

Fix: after 346.vd87693c5a_86c
Fix from $1,950 2022-03-15
Kubernetes Continuous Deploy MEDIUM 6.5
CVE-2022-27210

A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an …

Fix: after 2.3.1
Fix from $1,600 2022-03-15
Cloudbees Aws Credentials HIGH 8.0
CVE-2022-27198

A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Ove…

Fix: 1.28.2+
Fix from $1,950 2022-03-15
Spectrum Protect Operations Center HIGH 8.8
CVE-2022-22346

IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which could allow an attacker to exec…

Fix: 8.1.14.000+
Fix from $1,950 2022-03-14
X\/p Messenger HIGH 8.8
CVE-2021-45886

An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable to a weaken…

No fix yet
Fix from $1,950 2022-03-13
Wp Maps HIGH 8.8
CVE-2022-25600

Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (version…

Fix: 4.2.4+
Fix from $1,950 2022-03-11
Email Subscribers \& Newsletters HIGH 8.8
CVE-2022-0439

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_r…

Fix: 5.3.2+
Fix from $1,950 2022-03-07
Wordpress Real Cookie Banner MEDIUM 6.5
CVE-2022-0445

The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when reset…

Fix: 2.14.2+
Fix from $1,600 2022-03-07
Easy Pricing Tables MEDIUM 6.5
CVE-2021-25098

The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, allowing attackers to make a lo…

Fix: 3.1.3+
Fix from $1,600 2022-03-07
Subrion Cms HIGH 8.8
CVE-2020-18326

Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a re…

Mitigation only
Fix from $1,950 2022-03-04
Mini Inventory And Sales Management System MEDIUM 5.0
CVE-2021-44321

Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the invento…

No fix yet
Fix from $1,600 2022-03-04
Petereport MEDIUM 6.5
CVE-2022-23052

PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users into deleting users, products, …

No fix yet
Fix from $1,600 2022-03-03
Codeigniter HIGH 8.8
CVE-2022-24712

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attacker…

Fix: 4.1.9+
Fix from $1,950 2022-02-28
Post Snippets CRITICAL 9.6
CVE-2021-25010

The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arb…

Fix: 3.1.4+
Fix from $2,300 2022-02-28
Wp Google Map MEDIUM 5.7
CVE-2021-25011

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which co…

Fix: 1.8.1+
Fix from $1,600 2022-02-28
Wp Google Map MEDIUM 6.5
CVE-2021-25081

The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attacker…

Fix: 1.8.4+
Fix from $1,600 2022-02-28
Orange Form HIGH 8.8
CVE-2021-24704

In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query…

Fix: after 1.0
Fix from $1,950 2022-02-28
Core Tweaks Wp Setup HIGH 8.8
CVE-2021-24803

The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a…

Fix: after 4.1
Fix from $1,950 2022-02-28