Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Vigorconnect HIGH 8.8
CVE-2021-20126

Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent …

No fix yet
Fix from $1,950 2021-10-13
Og Tags HIGH 8.8
CVE-2021-20831

Cross-site request forgery (CSRF) vulnerability in OG Tags versions prior to 2.0.2 allows a remote attacker to hijack the authentication of administr…

Fix: 2.0.2+
Fix from $1,950 2021-10-13
Remote Service Manager HIGH 8.8
CVE-2021-20795

Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack t…

Mitigation only
Fix from $1,950 2021-10-13
Weather Effect MEDIUM 5.4
CVE-2021-24683

The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them,…

Fix: 1.3.4+
Fix from $1,600 2021-10-11
Software License Manager HIGH 8.8
CVE-2021-24711

The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable …

Fix: 4.5.1+
Fix from $1,950 2021-10-11
Webtareas HIGH 8.8
CVE-2021-41916

A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profil…

Fix: after 2.4
Fix from $1,950 2021-10-08
Sterling File Gateway HIGH 8.8
CVE-2021-20489

IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Fix: after 6.1.0.3
Fix from $1,950 2021-10-07
Wdja Cms MEDIUM 6.5
CVE-2020-21658

A Cross-Site Request Forgery (CSRF) in WDJA CMS v1.5.2 allows attackers to arbitrarily add administrator accounts via a crafted URL.

No fix yet
Fix from $1,600 2021-10-06
Sterling B2b Integrator HIGH 8.8
CVE-2021-29837

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to exe…

Fix: after 6.1.0.3
Fix from $1,950 2021-10-06
TYPO3 HIGH 8.8
CVE-2021-41113

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the new TYPO3 v11 feature tha…

Fix: 11.5.0+
Fix from $1,950 2021-10-05
Streaming Engine HIGH 8.1
CVE-2021-35491

A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via th…

Fix: 4.8.14+
Fix from $1,950 2021-10-05
Maccms HIGH 8.8
CVE-2020-21386

A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.

No fix yet
Fix from $1,950 2021-10-04
Ecs Router Controller Ecs Firmware HIGH 8.8
CVE-2021-41295

ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a forged request at a malicious we…

Mitigation only
Fix from $1,950 2021-09-30
Streama HIGH 8.8
CVE-2021-41764

A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does not have CSRF checks in place w…

Fix: after 1.10.3
Fix from $1,950 2021-09-29
Countdown And Countup\, Woocommerce Sales Timer HIGH 8.8
CVE-2021-34636

The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in…

Fix: after 1.5.7
Fix from $1,950 2021-09-28
Gila Cms HIGH 8.8
CVE-2020-20693

A Cross-Site Request Forgery (CSRF) in GilaCMS v1.11.4 allows authenticated attackers to arbitrarily add administrator accounts.

No fix yet
Fix from $1,950 2021-09-27
Ulisting HIGH 8.8
CVE-2021-36876

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin adminis…

Fix: after 2.0.5
Fix from $1,950 2021-09-27
Ulisting MEDIUM 6.5
CVE-2021-36877

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.

Fix: after 2.0.5
Fix from $1,600 2021-09-27
Concrete Cms HIGH 8.8
CVE-2021-40108

An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/even…

Fix: 8.5.6+
Fix from $1,950 2021-09-27
Firefly Iii HIGH 8.8
CVE-2021-3819

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 5.6.1+
Fix from $1,950 2021-09-27
Openvpn Monitor MEDIUM 6.5
CVE-2021-31604

furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.

Fix: after 1.1.3
Fix from $1,600 2021-09-27
Maccms HIGH 8.1
CVE-2020-20514

A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.

No fix yet
Fix from $1,950 2021-09-24
Yzmcms HIGH 8.8
CVE-2020-19951

A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.

No fix yet
Fix from $1,950 2021-09-23
Jazz For Service Management MEDIUM 6.5
CVE-2021-29816

IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery which could allow an attacker…

Patch available
Fix from $1,600 2021-09-23
Concrete Cms MEDIUM 5.4
CVE-2021-22953

A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Cr…

Fix: after 8.5.5
Fix from $1,600 2021-09-23
Concrete Cms MEDIUM 5.4
CVE-2021-22949

A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space…

Fix: after 8.5.5
Fix from $1,600 2021-09-23
Concrete Cms MEDIUM 6.5
CVE-2021-22950

Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery:…

Fix: 8.5.6+
Fix from $1,600 2021-09-23
Dada Mail HIGH 8.8
CVE-2021-41083

Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully crafted web page via email, S…

Fix: 11.16.0+
Fix from $1,950 2021-09-20
Donate With Qrcode MEDIUM 5.4
CVE-2021-24618

The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scri…

Fix: 1.4.5+
Fix from $1,600 2021-09-20
Print My Blog HIGH 8.1
CVE-2021-24636

The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactiv…

Fix: 3.4.2+
Fix from $1,950 2021-09-20