Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Support Board HIGH 8.1
CVE-2021-24823

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow atta…

Fix: 3.3.6+
Fix from $1,950 2022-02-28
Teamcity HIGH 8.8
CVE-2022-24342

In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.

Fix: 2021.2.1+
Fix from $1,950 2022-02-25
Jspwiki HIGH 8.8
CVE-2022-24947

Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2…

Fix: 2.11.2+
Fix from $1,950 2022-02-25
Nbg6816 Firmware HIGH 8.8
CVE-2021-4030

A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands…

Fix: 1.00+
Fix from $1,950 2022-02-24
Wp Content Copy Protection \& No Right Click HIGH 8.8
CVE-2022-23983

Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protection & No Right Click WordPress…

Fix: after 3.4.4
Fix from $1,950 2022-02-21
Anycomment HIGH 8.8
CVE-2022-0134

The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features, allowing attackers to make l…

Fix: 0.2.18+
Fix from $1,950 2022-02-21
Plesk MEDIUM 6.5
CVE-2021-45007

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel. NO…

No fix yet
Fix from $1,600 2022-02-20
Filecloud HIGH 8.8
CVE-2022-25241

In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).

Fix: 21.3.0.18447+
Fix from $1,950 2022-02-16
Filecloud HIGH 8.8
CVE-2022-25242

In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).

Fix: 21.3.0.18447+
Fix from $1,950 2022-02-16
Scratch Confirmaccount V3 MEDIUM 6.5
CVE-2021-46252

A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attackers to modify account reques…

Fix: 2022-01-04+
Fix from $1,600 2022-02-15
Dbcharts HIGH 8.8
CVE-2022-25205

A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified d…

Fix: after 0.5.2
Fix from $1,950 2022-02-15
Chef Sinatra HIGH 8.8
CVE-2022-25207

A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP reque…

Fix: after 1.20
Fix from $1,950 2022-02-15
Swamp HIGH 8.8
CVE-2022-25212

A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web …

Fix: after 1.2.6
Fix from $1,950 2022-02-15
Snow Commander HIGH 8.8
CVE-2022-25192

A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to connect to an attacker-specif…

Fix: after 1.10
Fix from $1,950 2022-02-15
Autonomiq HIGH 8.8
CVE-2022-25194

A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to connect to an attacker-specified U…

Fix: after 1.15
Fix from $1,950 2022-02-15
Scp Publisher HIGH 8.8
CVE-2022-25198

A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specifie…

Fix: after 1.8
Fix from $1,950 2022-02-15
Checkmarx HIGH 8.8
CVE-2022-25200

A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specifi…

Fix: after 2022.1.2
Fix from $1,950 2022-02-15
Yzmcms HIGH 8.8
CVE-2022-23384

YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add

No fix yet
Fix from $1,950 2022-02-15
Jira Data Center MEDIUM 6.5
CVE-2021-43941

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa an…

Fix: 8.13.5 / 8.20.3+
Fix from $1,600 2022-02-15
Remove Footer Credit MEDIUM 5.4
CVE-2021-24446

The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make…

Fix: 1.0.6+
Fix from $1,600 2022-02-14
Magnolia Cms HIGH 8.8
CVE-2021-46366

An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Fo…

Fix: 6.2.4+
Fix from $1,950 2022-02-11
Entity Embed MEDIUM 6.1
CVE-2020-13673

The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivil…

Patch available
Fix from $1,600 2022-02-11
Drupal MEDIUM 6.5
CVE-2020-13674

The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to p…

Fix: 8.9.19 / 9.1.13+
Fix from $1,600 2022-02-11
Hmibscea53d1edb Firmware HIGH 8.8
CVE-2022-22808

A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cro…

Fix: 4.0.0.13+
Fix from $1,950 2022-02-09
Spacelynk Firmware HIGH 8.1
CVE-2022-22811

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of t…

Fix: after 2.6.2
Fix from $1,950 2022-02-09
Concrete Cms HIGH 8.8
CVE-2021-22954

A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.

Fix: 9.0+
Fix from $1,950 2022-02-09
Grafana HIGH 8.8
CVE-2022-21703

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic…

Fix: 3.0 / 7.5.15+
Fix from $1,950 2022-02-08
Gitea HIGH 8.8
CVE-2021-45326

Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST…

Fix: 1.5.2+
Fix from $1,950 2022-02-08
Microweber MEDIUM 6.5
CVE-2022-0505

Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.

Fix: 1.2.11+
Fix from $1,600 2022-02-08
Country Blocker HIGH 7.1
CVE-2021-25108

The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, al…

Fix: 2.26.6+
Fix from $1,950 2022-02-07