Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Ec Cube MEDIUM 6.5
CVE-2021-20842

Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Adminis…

Fix: after 2.17.1
Fix from $1,600 2021-11-24
Unlimited Sitemap Generator HIGH 8.8
CVE-2021-20845

Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authenti…

Fix: 8.2+
Fix from $1,950 2021-11-24
Push Notifications For Wordpress HIGH 8.8
CVE-2021-20846

Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack…

Fix: 6.0.1+
Fix from $1,950 2021-11-24
Images To Webp HIGH 8.1
CVE-2021-24641

The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in …

Fix: 1.9+
Fix from $1,950 2021-11-23
Download Plugin MEDIUM 5.7
CVE-2021-24703

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any aut…

Fix: 1.6.1+
Fix from $1,600 2021-11-23
Moodle HIGH 8.8
CVE-2021-43559

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" fun…

Fix: 3.9.11 / 3.10.8+
Fix from $1,950 2021-11-22
Qmailagent HIGH 8.8
CVE-2021-34358

We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later

Fix: 3.0.2+
Fix from $1,950 2021-11-20
Client Relationship Management MEDIUM 5.4
CVE-2021-39198

OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an a…

Fix: after 4.2.5
Fix from $1,600 2021-11-19
Team Password Manager HIGH 8.8
CVE-2021-44036

Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.

Fix: 10.135.236+
Fix from $1,950 2021-11-19
Easy Registration Forms HIGH 8.8
CVE-2021-39353

The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form functi…

Fix: after 2.1.1
Fix from $1,950 2021-11-19
Kimai 2 MEDIUM 6.5
CVE-2021-3976

kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 1.16.2+
Fix from $1,600 2021-11-19
Wp Reset Pro HIGH 8.8
CVE-2021-36908

Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.

Fix: 5.99+
Fix from $1,950 2021-11-18
Solidus Auth Devise HIGH 8.8
CVE-2021-41274

solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devi…

Fix: 2.5.4+
Fix from $1,950 2021-11-17
Spree Auth Devise HIGH 8.8
CVE-2021-41275

spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by u…

Fix: 4.4.1+
Fix from $1,950 2021-11-17
Mousewheel Smooth Scroll MEDIUM 6.5
CVE-2021-24852

The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make …

Fix: 5.7+
Fix from $1,600 2021-11-17
Colorful Categories MEDIUM 6.5
CVE-2021-24802

The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make a logged in admin or editor …

Fix: 2.0.15+
Fix from $1,600 2021-11-17
Simple Jwt Login HIGH 8.8
CVE-2021-24804

The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin …

Fix: 3.2.1+
Fix from $1,950 2021-11-17
Calibre Web HIGH 8.8
CVE-2021-25965

In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an …

Fix: after 0.6.13
Fix from $1,950 2021-11-16
Piranha Cms HIGH 8.1
CVE-2021-25976

In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the ma…

Fix: after 9.2
Fix from $1,950 2021-11-16
Showdoc MEDIUM 6.5
CVE-2021-3683

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 2.9.12
Fix from $1,600 2021-11-13
Showdoc MEDIUM 5.4
CVE-2021-3775

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 2.9.12
Fix from $1,600 2021-11-13
Showdoc MEDIUM 5.4
CVE-2021-3776

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 2.9.12
Fix from $1,600 2021-11-13
Icms HIGH 8.8
CVE-2020-21141

iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.

No fix yet
Fix from $1,950 2021-11-12
Platinum 4410 Firmware MEDIUM 6.5
CVE-2020-28137

Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the rout…

No fix yet
Fix from $1,600 2021-11-10
Smart Box Firmware HIGH 8.8
CVE-2021-41426

Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.

No fix yet
Fix from $1,950 2021-11-10
Hsmx App 25 Firmware MEDIUM 6.5
CVE-2021-40518

Airangel HSMX Gateway devices through 5.2.04 allow CSRF.

Fix: after 5.2.04
Fix from $1,600 2021-11-10
Power Bi Report Server HIGH 7.6
CVE-2021-41372

A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing H…

Patch available
Fix from $1,950 2021-11-10
404 To 301 MEDIUM 6.5
CVE-2021-24766

The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which co…

Fix: 3.0.9+
Fix from $1,600 2021-11-08
Redirect 404 Error Page To Homepage Or Custom Page With Logs MEDIUM 6.5
CVE-2021-24767

The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which coul…

Fix: 1.7.9+
Fix from $1,600 2021-11-08
Chameleon Css HIGH 8.8
CVE-2021-24626

The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, s…

Fix: after 1.2
Fix from $1,950 2021-11-08