Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
711cms HIGH 8.8
CVE-2020-18460

Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content.

No fix yet
Fix from $1,950 2021-08-12
Bycms MEDIUM 6.8
CVE-2020-18454

Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.

No fix yet
Fix from $1,600 2021-08-12
Bycms MEDIUM 6.8
CVE-2020-18457

Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html.

No fix yet
Fix from $1,600 2021-08-12
Sapphireims MEDIUM 6.5
CVE-2020-25562

In SapphireIMS 5.0, there is no CSRF token present in the entire application. This can lead to CSRF vulnerabilities in critical application forms lik…

No fix yet
Fix from $1,600 2021-08-11
Ex3700 Firmware HIGH 8.0
CVE-2021-32122

Certain NETGEAR devices are affected by CSRF. This affects EX3700 before 1.0.0.90, EX3800 before 1.0.0.90, EX6120 before 1.0.0.64, and EX6130 before …

Fix: 1.0.0.44 / 1.0.0.64+
Fix from $1,950 2021-08-11
My Smtp Contact MEDIUM 6.5
CVE-2021-29400

A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP s…

No fix yet
Fix from $1,600 2021-08-10
Ctparental HIGH 8.8
CVE-2021-37366

CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining CSRF with XSS, an attacker c…

Fix: 4.45.03+
Fix from $1,950 2021-08-10
Leaflet Map MEDIUM 6.5
CVE-2021-24467

The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in adm…

Fix: 3.0.0+
Fix from $1,600 2021-08-09
Workreap HIGH 8.1
CVE-2021-24500

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object refer…

Fix: 2.2.2+
Fix from $1,950 2021-08-09
Wage Cms MEDIUM 6.5
CVE-2020-21358

A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.

No fix yet
Fix from $1,600 2021-08-06
Ignitedcms HIGH 8.8
CVE-2020-18694

Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/a…

No fix yet
Fix from $1,950 2021-08-06
Graduate Management Information System HIGH 8.8
CVE-2021-37381

Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For example: any…

No fix yet
Fix from $1,950 2021-08-06
Youtube Feeder HIGH 8.8
CVE-2021-34633

The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in the ~/youtube-feeder.php fil…

Fix: after 2.0.1
Fix from $1,950 2021-08-05
Sola Newsletters HIGH 8.8
CVE-2021-34634

The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.p…

Fix: after 4.0.23
Fix from $1,950 2021-08-05
Newsplugin HIGH 8.8
CVE-2021-34631

The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in the ~/news-plugin.php file wh…

Fix: after 1.0.18
Fix from $1,950 2021-08-05
Cpp4 Firmware HIGH 8.8
CVE-2021-23849

A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another us…

Mitigation only
Fix from $1,950 2021-08-05
Digital Experience Platform HIGH 7.5
CVE-2021-33338

The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in…

Fix: after 7.3.2
Fix from $1,950 2021-08-04
Admin Custom Login HIGH 8.8
CVE-2021-34628

The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-…

Fix: after 3.2.7
Fix from $1,950 2021-08-02
Seo Backlinks HIGH 8.8
CVE-2021-34632

The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file whic…

Fix: after 4.0.1
Fix from $1,950 2021-08-02
Post Index HIGH 8.8
CVE-2021-34637

The Post Index WordPress plugin is vulnerable to Cross-Site Request Forgery via the OptionsPage function found in the ~/php/settings.php file which a…

Fix: after 0.7.5
Fix from $1,950 2021-08-02
Qradar User Behavior Analytics HIGH 8.8
CVE-2021-29757

IBM QRadar User Behavior Analytics 4.1.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthori…

Patch available
Fix from $1,950 2021-08-02
Wp Learn Manager MEDIUM 6.1
CVE-2021-24504

The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payl…

Fix: after 1.1.2
Fix from $1,600 2021-08-02
Migrate Users MEDIUM 6.1
CVE-2021-24477

The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cr…

Fix: after 1.0.1
Fix from $1,600 2021-08-02
Optical Bb Unit E Wmta Firmware HIGH 8.8
CVE-2021-20783

Cross-site request forgery (CSRF) vulnerability in Optical BB unit E-WMTA2.3 allows a remote attacker to hijack the authentication of administrators …

Mitigation only
Fix from $1,950 2021-07-30
Metinfo HIGH 8.8
CVE-2020-18157

Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.

No fix yet
Fix from $1,950 2021-07-30
Flatpress HIGH 8.8
CVE-2020-22761

Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.

Patch available
Fix from $1,950 2021-07-30
Itop HIGH 8.8
CVE-2021-32776

Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.4, CSRF tokens can be reused by a malicious user, as on Windows serv…

Fix: 2.7.4+
Fix from $1,950 2021-07-21
Itop MEDIUM 6.5
CVE-2021-21407

Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation can be bypassed through iTop …

Fix: 2.7.4+
Fix from $1,600 2021-07-21
Stock Manager For Woocommerce HIGH 8.8
CVE-2021-34619

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and in…

Fix: after 2.5.7
Fix from $1,950 2021-07-21
Geckodriver HIGH 8.8
CVE-2020-15660

Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically p…

Fix: 0.27.0+
Fix from $1,950 2021-07-20