Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Genie Wp Favicon MEDIUM 6.5
CVE-2021-24674

The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logg…

Fix: after 0.5.2
Fix from $1,600 2021-11-08
Ec Cloud E Commerce System MEDIUM 6.5
CVE-2020-21139

EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin account…

No fix yet
Fix from $1,600 2021-11-04
Unified Communications Manager MEDIUM 6.5
CVE-2021-34773

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Sess…

Mitigation only
Fix from $1,600 2021-11-04
Ayacms HIGH 8.8
CVE-2020-23686

Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.

No fix yet
Fix from $1,950 2021-11-02
Infosphere Information Server HIGH 8.8
CVE-2021-29888

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Patch available
Fix from $1,950 2021-11-02
Better Messages HIGH 8.8
CVE-2021-24809

The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_be…

Fix: 1.9.9.41+
Fix from $1,950 2021-11-01
Wp Pro Quiz MEDIUM 6.5
CVE-2020-36504

The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow an attacker to make a logged …

Fix: after 0.37
Fix from $1,600 2021-11-01
Delete All Comments Easily MEDIUM 6.5
CVE-2020-36505

The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthentic…

Fix: after 1.3
Fix from $1,600 2021-11-01
Flat Preloader MEDIUM 5.4
CVE-2021-24685

The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does not sanitise and escape them…

Fix: 1.5.4+
Fix from $1,600 2021-11-01
Firefly Iii HIGH 8.8
CVE-2021-3901

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 5.6.2
Fix from $1,950 2021-10-27
Firefly Iii MEDIUM 6.5
CVE-2021-3900

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 5.6.2
Fix from $1,600 2021-10-27
St Daily Tip HIGH 8.8
CVE-2021-24487

The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and…

Fix: after 4.7
Fix from $1,950 2021-10-25
Jquery Reply To Comment MEDIUM 6.1
CVE-2021-24543

The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor sanitise or escape its 'Quote St…

Fix: after 1.31
Fix from $1,600 2021-10-25
Wp Debugging MEDIUM 6.5
CVE-2021-24779

The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF che…

Fix: 2.11.0+
Fix from $1,600 2021-10-25
Formidable Form Builder CRITICAL 9.6
CVE-2021-24884

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could …

Fix: 4.09.05+
Fix from $2,300 2021-10-25
Arris Surfboard Sb8200 Firmware HIGH 8.8
CVE-2021-20120

The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an …

No fix yet
Fix from $1,950 2021-10-21
Jira Data Center MEDIUM 6.5
CVE-2021-39126

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF)…

Fix: 8.5.10 / 8.13.1+
Fix from $1,600 2021-10-21
Webex Meetings HIGH 7.1
CVE-2021-34743

A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an extern…

Mitigation only
Fix from $1,950 2021-10-21
Debian Linux HIGH 8.0
CVE-2021-42097

GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain …

Fix: 2.1.35+
Fix from $1,950 2021-10-21
Ir615 Firmware HIGH 8.8
CVE-2021-38480

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submi…

Mitigation only
Fix from $1,950 2021-10-19
Snipe It HIGH 8.8
CVE-2021-3858

snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 5.3.0+
Fix from $1,950 2021-10-19
Catch Scroll Progress Bar MEDIUM 5.7
CVE-2021-24752

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authentic…

Fix: 1.4 / 1.6+
Fix from $1,600 2021-10-18
Wp Cookie Choice MEDIUM 6.5
CVE-2021-24595

The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in…

Fix: after 1.1.0
Fix from $1,600 2021-10-18
Wechat Reward MEDIUM 5.4
CVE-2021-24615

The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to ma…

Fix: after 1.7
Fix from $1,600 2021-10-18
Scroll Banner MEDIUM 6.5
CVE-2021-24642

The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or v…

Fix: after 1.0
Fix from $1,600 2021-10-18
One User Avatar MEDIUM 6.5
CVE-2021-24675

The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is emb…

Fix: 2.3.7+
Fix from $1,600 2021-10-18
Compact Wp Audio Player MEDIUM 6.5
CVE-2021-24735

The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin chan…

Fix: 1.9.7+
Fix from $1,600 2021-10-18
Commerce MEDIUM 6.5
CVE-2021-39864

Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-site request forgery (CSRF) vul…

Fix: after 2.3.7
Fix from $1,600 2021-10-15
Kindeditor HIGH 8.8
CVE-2021-42228

A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.html.

Fix: after 4.1.12
Fix from $1,950 2021-10-14
Phpmywind MEDIUM 6.5
CVE-2020-19964

A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account withou…

No fix yet
Fix from $1,600 2021-10-14