Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Simple Log HIGH 8.8
CVE-2020-18265

Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-L…

No fix yet
Fix from $1,950 2021-06-07
Bloofoxcms MEDIUM 6.5
CVE-2020-36140

BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to…

No fix yet
Fix from $1,600 2021-06-04
Data Grid HIGH 7.1
CVE-2020-10771

A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw…

Mitigation only
Fix from $1,950 2021-06-02
Wp Login Security And History MEDIUM 6.2
CVE-2021-24328

The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation o…

Fix: after 1.0
Fix from $1,600 2021-06-01
Content Copy Protection \& Prevent Image Save MEDIUM 6.5
CVE-2021-24333

The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any valid…

Fix: after 1.3
Fix from $1,600 2021-06-01
Icms HIGH 8.8
CVE-2020-26641

A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.

No fix yet
Fix from $1,950 2021-05-28
3scale HIGH 8.8
CVE-2019-14836

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to…

Mitigation only
Fix from $1,950 2021-05-26
Joomla\! MEDIUM 6.5
CVE-2021-26033

An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX reordering endpoint.

Fix: after 3.9.26
Fix from $1,600 2021-05-26
Joomla\! MEDIUM 6.5
CVE-2021-26034

An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data download endpoints in com_banners …

Fix: after 3.9.26
Fix from $1,600 2021-05-26
Openoversight HIGH 8.1
CVE-2021-20096

Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into…

No fix yet
Fix from $1,950 2021-05-25
College Management System MEDIUM 6.5
CVE-2020-25408

A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, …

Mitigation only
Fix from $1,600 2021-05-24
Online Examination System MEDIUM 6.5
CVE-2020-25411

Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.

Mitigation only
Fix from $1,600 2021-05-24
Xtremio Management Server HIGH 8.8
CVE-2021-21549

Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged attacker could potentially ex…

Fix: 6.3.3-8+
Fix from $1,950 2021-05-21
Horizon HIGH 8.8
CVE-2021-25931

In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-…

Fix: 27.1.1 / 2019.1.19+
Fix from $1,950 2021-05-20
Fastify Csrf MEDIUM 6.5
CVE-2021-29624

fastify-csrf is an open-source plugin helps developers protect their Fastify server against CSRF attacks. Versions of fastify-csrf prior to 3.1.0 hav…

Fix: 3.1.0+
Fix from $1,600 2021-05-19
Pluck HIGH 8.8
CVE-2020-18195

Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the compone…

No fix yet
Fix from $1,950 2021-05-17
Pluck HIGH 8.8
CVE-2020-18198

Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component …

No fix yet
Fix from $1,950 2021-05-17
All 404 Redirect To Homepage MEDIUM 6.5
CVE-2021-24324

The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to make a logged in user change t…

Fix: after 1.3
Fix from $1,600 2021-05-17
Rf 301k Firmware HIGH 8.8
CVE-2021-32402

Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure configurations in i…

No fix yet
Fix from $1,950 2021-05-17
Rf 301k Firmware HIGH 8.8
CVE-2021-32403

Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token protection an…

No fix yet
Fix from $1,950 2021-05-17
Dedecms HIGH 8.8
CVE-2021-32073

DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code e…

No fix yet
Fix from $1,950 2021-05-15
Forestblog HIGH 8.8
CVE-2020-18964

Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote maliciou…

No fix yet
Fix from $1,950 2021-05-11
Xray Test Management For Jira HIGH 7.1
CVE-2021-21652

A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to …

Fix: after 2.4.0
Fix from $1,950 2021-05-11
P4 HIGH 7.1
CVE-2021-21655

A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perfor…

Fix: after 1.11.4
Fix from $1,950 2021-05-11
Nonecms MEDIUM 6.1
CVE-2020-23376

NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected wit…

No fix yet
Fix from $1,600 2021-05-10
Phpok HIGH 8.8
CVE-2020-19199

A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execu…

No fix yet
Fix from $1,950 2021-05-10
Emissary HIGH 8.8
CVE-2021-32096

The ConsoleAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows a CSRF attack that results in injecting arbitrary Ruby code …

No fix yet
Fix from $1,950 2021-05-07
Fork Cms HIGH 8.8
CVE-2020-23264

Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.

Fix: 5.8.2+
Fix from $1,950 2021-05-06
Puppycms MEDIUM 6.5
CVE-2020-18889

Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.

No fix yet
Fix from $1,600 2021-05-06
Business Directory Plugin Easy Listing Directories HIGH 8.8
CVE-2021-24178

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues…

Fix: 5.11.1+
Fix from $1,950 2021-05-06