Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Datadump MEDIUM 5.4
CVE-2021-32774

DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b, DataDump had no protection …

Fix: 2021-07-07+
Fix from $1,600 2021-07-20
Infosphere Master Data Management Server MEDIUM 6.5
CVE-2020-4675

IBM InfoSphere Master Data Management Server 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Mitigation only
Fix from $1,600 2021-07-16
Thinkcmf MEDIUM 6.5
CVE-2020-18151

Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.

No fix yet
Fix from $1,600 2021-07-14
Booking Core MEDIUM 6.5
CVE-2020-27379

Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF token is not being validated …

Mitigation only
Fix from $1,600 2021-07-14
Wordpress Meta Data And Taxonomies Filter HIGH 8.8
CVE-2021-20781

Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.2.8 and versions prior to v.2…

Fix: 1.2.8 / 2.2.8+
Fix from $1,950 2021-07-14
Software License Manager HIGH 8.8
CVE-2021-20782

Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authenticat…

Fix: 4.4.6+
Fix from $1,950 2021-07-14
Glass MEDIUM 6.1
CVE-2021-24434

The Glass WordPress plugin through 1.3.2 does not sanitise or escape its "Glass Pages" setting before outputting in a page, leading to a Stored Cross…

Fix: after 1.3.2
Fix from $1,600 2021-07-12
Mq Appliance HIGH 8.8
CVE-2020-4938

IBM MQ Appliance 9.1 and 9.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions …

Fix: 9.1.0.8 / 9.2.0.2+
Fix from $1,950 2021-07-12
Contact Form HIGH 8.8
CVE-2021-34620

The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Priv…

Fix: 3.6.67+
Fix from $1,950 2021-07-07
GitLab MEDIUM 6.5
CVE-2021-22224

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacke…

Fix: 13.12.6 / 14.0.2+
Fix from $1,600 2021-07-07
Wordpress Email Template Designer HIGH 8.8
CVE-2021-20779

Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers t…

Fix: 3.0.8+
Fix from $1,950 2021-07-07
Wordpress Currency Switcher HIGH 8.8
CVE-2021-20780

Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authent…

Fix: after 1.1.6
Fix from $1,950 2021-07-07
Vikrentcar Car Rental Management System MEDIUM 5.4
CVE-2021-24388

In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields th…

Fix: 1.1.7+
Fix from $1,600 2021-07-06
Xwiki MEDIUM 5.7
CVE-2021-32730

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability e…

Fix: 12.10.5+
Fix from $1,600 2021-07-01
Requests MEDIUM 6.5
CVE-2021-21675

A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or hav…

Fix: after 2.2.12
Fix from $1,600 2021-06-30
Machform HIGH 8.8
CVE-2021-20102

Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.

Fix: 16+
Fix from $1,950 2021-06-29
Juqingcms HIGH 8.8
CVE-2020-18648

Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "JuQingCMS_v1.0/admin/index.ph…

No fix yet
Fix from $1,950 2021-06-22
Icehrm HIGH 8.8
CVE-2021-34244

A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts or change u…

No fix yet
Fix from $1,950 2021-06-22
White Shark Systems MEDIUM 6.5
CVE-2020-20468

White Shark System (WSS) 1.3.2 is vulnerable to CSRF. Attackers can use the user_edit_password.php file to modify the user password.

No fix yet
Fix from $1,600 2021-06-21
Tw100 S4w1ca Firmware HIGH 8.8
CVE-2021-32424

In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized changes to an affected router via a…

Mitigation only
Fix from $1,950 2021-06-17
Bloofoxcms MEDIUM 6.5
CVE-2020-35759

bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).

No fix yet
Fix from $1,600 2021-06-16
Gallery From Files MEDIUM 6.1
CVE-2021-24349

This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sani…

Fix: after 1.6.0
Fix from $1,600 2021-06-14
Drupal HIGH 8.8
CVE-2020-13663

Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead…

Fix: 7.72 / 8.8.8+
Fix from $1,950 2021-06-11
Tl Sg2005 Firmware HIGH 8.8
CVE-2021-31659

TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration information i…

Mitigation only
Fix from $1,950 2021-06-10
Xebialabs Xl Deploy HIGH 8.8
CVE-2021-21665

A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker…

Fix: after 10.0.1
Fix from $1,950 2021-06-10
Fedora HIGH 8.1
CVE-2021-32677

FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cooki…

Fix: 0.65.2+
Fix from $1,950 2021-06-09
Cloverdx HIGH 8.8
CVE-2021-29995

A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the logged-in …

Fix: 5.7.1 / 5.8.2+
Fix from $1,950 2021-06-09
Bdr Suite HIGH 8.8
CVE-2021-26474

Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products or versions of products in thi…

Fix: 4.2.0+
Fix from $1,950 2021-06-08
Codebeamer HIGH 8.8
CVE-2020-26516

A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF t…

No fix yet
Fix from $1,950 2021-06-08
Simple Log HIGH 8.8
CVE-2020-18264

Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-L…

No fix yet
Fix from $1,950 2021-06-07