Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Nested Pages HIGH 8.1
CVE-2021-38342

The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` action…

Fix: after 3.1.15
Fix from $1,950 2021-08-30
Indexhibit MEDIUM 6.5
CVE-2020-18123

A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.

No fix yet
Fix from $1,600 2021-08-30
Indexhibit MEDIUM 5.7
CVE-2020-18124

A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.

No fix yet
Fix from $1,600 2021-08-30
Blue Admin HIGH 8.8
CVE-2021-24581

The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Store…

Fix: after 21.06.01
Fix from $1,950 2021-08-30
Manageengine Log360 HIGH 8.8
CVE-2021-40172

Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.

Fix: after 5.1
Fix from $1,950 2021-08-29
Manageengine Cloud Security Plus HIGH 8.8
CVE-2021-40173

Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

Fix: after 4.0
Fix from $1,950 2021-08-29
Manageengine Log360 HIGH 8.8
CVE-2021-40174

Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.

Fix: after 5.1
Fix from $1,950 2021-08-29
Yourls HIGH 8.8
CVE-2021-3734

yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames

Fix: after 1.8.1
Fix from $1,950 2021-08-26
Dedecms HIGH 8.8
CVE-2020-18917

The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the content…

No fix yet
Fix from $1,950 2021-08-24
Joplin HIGH 8.8
CVE-2021-23431

The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms.

Fix: 2.3.2+
Fix from $1,950 2021-08-24
Firefly Iii MEDIUM 6.5
CVE-2021-3728

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Patch available
Fix from $1,600 2021-08-23
Firefly Iii MEDIUM 6.5
CVE-2021-3730

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Patch available
Fix from $1,600 2021-08-23
Contact Form 7 Captcha HIGH 8.8
CVE-2021-24565

The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a …

Fix: 0.0.9+
Fix from $1,950 2021-08-23
Diary Availability Calendar HIGH 8.8
CVE-2021-24555

The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL st…

Fix: after 1.0.3
Fix from $1,950 2021-08-23
Nexto Nx3003 Firmware MEDIUM 6.5
CVE-2021-39243

Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.1…

No fix yet
Fix from $1,600 2021-08-23
Ponzu HIGH 8.1
CVE-2020-24130

A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator c…

No fix yet
Fix from $1,950 2021-08-20
Eyoucms HIGH 8.8
CVE-2020-20642

Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filem…

No fix yet
Fix from $1,950 2021-08-19
Csrfguard HIGH 8.8
CVE-2021-28490

In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token.

Fix: after 3.1.0
Fix from $1,950 2021-08-19
Shopping Cart \& Ecommerce Store HIGH 8.8
CVE-2021-34645

The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the…

Fix: after 5.1.0
Fix from $1,950 2021-08-19
Eyoucms HIGH 8.8
CVE-2020-19669

Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang…

No fix yet
Fix from $1,950 2021-08-18
Garoon HIGH 8.0
CVE-2021-20758

Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authe…

Fix: after 5.0.2
Fix from $1,950 2021-08-18
Seacms MEDIUM 6.5
CVE-2020-28846

Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account.

No fix yet
Fix from $1,600 2021-08-17
Datapower Gateway MEDIUM 6.5
CVE-2020-4992

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a…

Fix: after 2018.4.1.16
Fix from $1,600 2021-08-17
Custom Login Redirect MEDIUM 6.1
CVE-2021-24536

The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape us…

Fix: after 1.0.0
Fix from $1,600 2021-08-16
Telugu Bible Verse Daily MEDIUM 6.1
CVE-2021-24410

The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape t…

Fix: after 1.0
Fix from $1,600 2021-08-16
Social Tape MEDIUM 6.1
CVE-2021-24411

The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before o…

Fix: after 1.0
Fix from $1,600 2021-08-16
Verse O Matic MEDIUM 6.1
CVE-2021-24466

The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwan…

Fix: after 4.1.1
Fix from $1,600 2021-08-16
Light Messages MEDIUM 6.1
CVE-2021-24535

The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them …

Fix: after 1.0
Fix from $1,600 2021-08-16
Express Cart HIGH 8.8
CVE-2020-22403

Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other …

Fix: after 1.1.10
Fix from $1,950 2021-08-12
Damicms HIGH 8.0
CVE-2020-18458

Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.

No fix yet
Fix from $1,950 2021-08-12