Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Tarteaucitron.js Cookies Legislation \& Gdpr HIGH 8.8
CVE-2021-36887

Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR Wor…

Fix: after 1.5.4
Fix from $1,950 2021-12-20
Live Helper Chat HIGH 8.8
CVE-2021-4131

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 2.0+
Fix from $1,950 2021-12-18
Snipe It HIGH 8.8
CVE-2021-4130

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 5.3.6+
Fix from $1,950 2021-12-18
User Management System In Php Stored Procedure MEDIUM 6.5
CVE-2021-26800

Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using stored procedure V1.0, allow…

Mitigation only
Fix from $1,600 2021-12-16
Galette HIGH 8.8
CVE-2021-41260

Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check …

Fix: 0.9.6+
Fix from $1,950 2021-12-16
Live Helper Chat MEDIUM 6.5
CVE-2021-4123

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 2.0+
Fix from $1,600 2021-12-16
Catfish Cms HIGH 8.8
CVE-2021-45017

Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a goog…

Fix: after 6.3.0
Fix from $1,950 2021-12-15
Pixel Cat CRITICAL 9.0
CVE-2021-24922

The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, w…

Fix: 2.6.2+
Fix from $2,300 2021-12-13
Like Button Rating HIGH 8.0
CVE-2021-24945

The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX acti…

Fix: 2.6.38+
Fix from $1,950 2021-12-13
Wp Admin Logo Changer MEDIUM 6.5
CVE-2021-24784

The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logge…

Fix: after 1.0
Fix from $1,600 2021-12-13
Filter Portfolio Gallery MEDIUM 6.5
CVE-2021-24795

The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleting a Gallery, which could all…

Fix: after 1.5
Fix from $1,600 2021-12-13
Kimai 2 MEDIUM 6.5
CVE-2021-4033

kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 1.16.7+
Fix from $1,600 2021-12-09
Zzzcms HIGH 8.8
CVE-2020-19682

A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.

No fix yet
Fix from $1,950 2021-12-09
Live Helper Chat MEDIUM 6.5
CVE-2021-4049

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 2.0+
Fix from $1,600 2021-12-07
B2evolution Cms HIGH 8.8
CVE-2021-31631

b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to …

No fix yet
Fix from $1,950 2021-12-06
Serv U HIGH 8.8
CVE-2021-35242

Serv-U server responds with valid CSRFToken when the request contains only Session.

Fix: 15.2.5+
Fix from $1,950 2021-12-06
Tawk.to Live Chat HIGH 8.0
CVE-2021-24914

The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX act…

Fix: 0.6.0+
Fix from $1,950 2021-12-06
Cognos Analytics HIGH 8.8
CVE-2021-29756

IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execu…

Fix: 11.1.7+
Fix from $1,950 2021-12-03
Clickbank Affiliate Ads CRITICAL 9.6
CVE-2015-20105

The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admi…

Fix: after 1.20
Fix from $2,300 2021-12-02
Bookstack MEDIUM 6.8
CVE-2021-3944

bookstack is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 21.11+
Fix from $1,600 2021-12-02
Debian Linux HIGH 8.8
CVE-2021-44227

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin passwo…

Fix: 2.1.38+
Fix from $1,950 2021-12-02
Hostel Management System HIGH 8.8
CVE-2021-43137

Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile…

No fix yet
Fix from $1,950 2021-12-01
Showdoc MEDIUM 6.5
CVE-2021-3993

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 2.9.13+
Fix from $1,600 2021-12-01
Showdoc HIGH 8.8
CVE-2021-4017

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 2.9.13+
Fix from $1,950 2021-12-01
Wrc 1167gst2 Firmware HIGH 8.8
CVE-2021-20860

Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior,…

Fix: after 2.11
Fix from $1,950 2021-12-01
Browser And Operating System Finder HIGH 8.8
CVE-2021-20851

Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker…

Fix: 1.2+
Fix from $1,950 2021-12-01
Contact Form With Captcha HIGH 8.8
CVE-2021-42358

The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php fil…

Fix: after 1.6.2
Fix from $1,950 2021-11-29
Stetic HIGH 8.8
CVE-2021-42364

The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/st…

Fix: after 1.0.6
Fix from $1,950 2021-11-29
Stylish Cost Calculator MEDIUM 5.4
CVE-2021-24822

The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its AJAX actions (available to a…

Fix: 7.0.4+
Fix from $1,600 2021-11-29
Redash MEDIUM 6.1
CVE-2021-43777

Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly …

Fix: after 10.0.0
Fix from $1,600 2021-11-24