Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Country Blocker HIGH 7.1
CVE-2021-25095

The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_ru…

Fix: 2.26.5+
Fix from $1,950 2022-02-07
Responsive Vector Maps MEDIUM 6.5
CVE-2021-24947

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in…

Fix: 6.4.2+
Fix from $1,600 2022-02-07
Ultimate Product Catalog MEDIUM 6.5
CVE-2021-24993

The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any a…

Fix: 5.0.26+
Fix from $1,600 2022-02-07
Supportcandy MEDIUM 6.5
CVE-2021-24843

The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged…

Fix: 2.2.7+
Fix from $1,600 2022-02-07
Supportcandy HIGH 8.8
CVE-2021-24879

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some…

Fix: 2.2.7+
Fix from $1,950 2022-02-07
Xwiki MEDIUM 6.5
CVE-2021-32732

### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which username(s) is actually tied to tha…

Fix: 12.10.5+
Fix from $1,600 2022-02-04
Modicon M340 Bmxp342020 Firmware HIGH 8.8
CVE-2020-7534

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized a…

Patch available
Fix from $1,950 2022-02-04
Filebrowser HIGH 8.8
CVE-2021-46398EPSS 7%

A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and ge…

Fix: 2.18.0+
Fix from $1,950 2022-02-04
Backdrop HIGH 8.8
CVE-2021-45268

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on t…

No fix yet
Fix from $1,950 2022-02-03
Financial Transaction Manager HIGH 8.8
CVE-2021-39044

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…

Mitigation only
Fix from $1,950 2022-02-02
Symfony HIGH 8.8
CVE-2022-23601

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protecti…

Fix: 5.3.15 / 5.4.4+
Fix from $1,950 2022-02-01
Social Networks Auto Poster MEDIUM 6.5
CVE-2021-25072

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker …

Fix: 4.3.25+
Fix from $1,600 2022-02-01
Link Library MEDIUM 6.5
CVE-2021-25092

The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin…

Fix: 7.2.8+
Fix from $1,600 2022-02-01
Labtools MEDIUM 6.5
CVE-2021-25097

The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authent…

Fix: after 1.0
Fix from $1,600 2022-02-01
Error Log Viewer MEDIUM 6.5
CVE-2021-24761

The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention,…

Fix: 1.1.2+
Fix from $1,600 2022-02-01
Perfect Survey HIGH 8.8
CVE-2021-24763

The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing …

Fix: 1.5.2+
Fix from $1,950 2022-02-01
Yzmcms MEDIUM 6.5
CVE-2022-23887

YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin…

No fix yet
Fix from $1,600 2022-01-28
Yzmcms HIGH 8.8
CVE-2022-23888

YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.

No fix yet
Fix from $1,950 2022-01-28
Evc1s22p4 Firmware HIGH 8.8
CVE-2021-22724

A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their b…

Fix: 3.4.0.2+
Fix from $1,950 2022-01-28
Evc1s22p4 Firmware HIGH 8.8
CVE-2021-22725

A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their b…

Fix: 3.4.0.2+
Fix from $1,950 2022-01-28
Spip HIGH 8.8
CVE-2021-44122

SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/…

Patch available
Fix from $1,950 2022-01-26
Moodle HIGH 8.8
CVE-2022-0335

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" f…

Fix: 3.9.12 / 3.10.9+
Fix from $1,950 2022-01-25
Yetiforce Customer Relationship Management HIGH 8.0
CVE-2022-0269

Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.

Fix: 6.3.0+
Fix from $1,950 2022-01-24
Accept Donations With Paypal MEDIUM 6.5
CVE-2021-24989

The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belo…

Fix: 1.3.4+
Fix from $1,600 2022-01-24
Qubely MEDIUM 6.5
CVE-2021-25013

The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure…

Fix: 1.7.8+
Fix from $1,600 2022-01-24
Wp125 HIGH 8.8
CVE-2021-25073

The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a lo…

Fix: 1.5.5+
Fix from $1,950 2022-01-24
Simple Download Monitor HIGH 8.8
CVE-2021-24696

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) ma…

Fix: 3.9.9+
Fix from $1,950 2022-01-24
Wp Extra File Types HIGH 8.0
CVE-2021-24936

The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which …

Fix: 0.5.1+
Fix from $1,950 2022-01-24
Ultimate Faq MEDIUM 5.7
CVE-2021-24968

The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_…

Fix: 2.1.2+
Fix from $1,600 2022-01-24
Mysiteforme MEDIUM 6.5
CVE-2021-46027

mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrato…

No fix yet
Fix from $1,600 2022-01-19